Malware expert Marco Ramilli collected a small set of VBA Macros widely re-used to weaponize Maldoc (Malware Document) in cyber attacks. The core concept of a dropper is to Download and to Execute a third party payload (or a second stage) The main idea behind this function is to invoke ServerXMLHTTP object to download a file from an external resource, to save it on local directory (ADODB) and finally to execute it through the object WScriptShell.”]
Source: https://securityaffairs.co/wordpress/91953/malware/vba-macros-office-malware.html

