A malicious word document with a VBA form, (Mon, Apr 16th)

Malware authors will often hide strings (like URLs) or even a full payload as property values of VBA forms. The stream that contains this information can be easily recognized with, the name ends with /o:

