Tools: oledump.py, re-search.py, hex-to-bin.py, translate.py, xorsearch, strings.py
Diary entries: “VBA Maldoc & UTF7 (APT-C-35)“, “Update: VBA Maldoc & UTF7 (APT-C-35)“
Sample: 394c97cc9d567e556a357f129aea03f737cbd2a1761df32146ef69d93afc73dc, MalwareBazaar