They try to download content from hxxp://mastercash2984.cepcerto\.info/01/, which isn't active any more. I will create detections for the files though (both encoded VBE files and deobfuscated VB scripts).
I have already sent via virus@avast.com
so far no reaction,wait the next update.
Thank you
_____________________________________
avast detects both as VBS:Malware-gen in VPS update 150822-0
release date 22/08/15