The macro is heavily obfuscated with string reversals and character replacements to hide its true intent. :
Manual cleaning of the script typically reveals a PowerShell command designed to download a secondary stage from a remote URL. 19032301.7z
Using tools like olevba or oledump reveals that the document contains an macro. The macro is heavily obfuscated with string reversals
: The malware often uses a specific hardcoded User-Agent for its web requests. 19032301.7z