MALICIOUS
322
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
T1059.005 Visual Basic
The critical heuristic OLE_VBA_BASE64_SHELL_COMMAND_STAGER indicates that the Workbook_Open macro decodes and executes a Base64-encoded PowerShell command. This suggests the file is designed to download and execute a second-stage payload. The presence of VBA macros and a Workbook_Open auto-execution further supports this. The ClamAV detection as Xls.Dropper.Agent-7144313-0 reinforces the malicious nature.
Heuristics 8
-
ClamAV: Xls.Dropper.Agent-7144313-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Xls.Dropper.Agent-7144313-0
-
VBA macros detected medium 5 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
VBA Base64-decoded Shell command stager critical OLE_VBA_BASE64_SHELL_COMMAND_STAGERVBA auto-exec macro decodes Base64 string literals into command or script-launch text and executes the result with Shell. This catches cmd/cscript/PowerShell/VBS launchers hidden from plain keyword matching.
-
Workbook_Open macro high OLE_VBA_WBOPENWorkbook_Open macro
-
CreateObject call high OLE_VBA_CREATEOBJCreateObject call
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 15808 bytes |
SHA-256: d73e184440bd4d9267f234eabc00929219a389f0cced5e4ddfd9d5500fa10293 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 5 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisWorkbook"
Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Private Sub workbook_open()
LkRU.RfqyRsDwg4Kc3yT6Yz9g
Do Until "UXXMM1hgdEhQHc" <> "qhRg"
Dim BitSn5y_gsS9T1_W6FRkD2eNCwlJtUlWFQ78HBtbXHRxMduqQ As CheckBox
Dim tfiNqbICeOzQmSKF62B4BN3VyK5hqAhA As Worksheet
Loop
Do Until "yBGXyv4m" <> "v3ItyFqPlrwOelLYegkUdqxVtSUDx"
Dim bLFFjFbnZ_a_s5 As CheckBox
Dim RFmcKyq3PJhH__w_dtlbHeoG4dttDaIUuueOEyINEi56haBW1YjpV As Worksheet
Loop
Do Until "OvwadipD7xyALVRhg3ojVUiisibb" <> "V2m1b8"
Dim d9rwkObIHtE5UDsxSf4E93KLr4FMqDJ8gM2SzsQXFLLybw As CheckBox
Dim MWsggF6U8jvd_pHMaDiGVFKY7 As Worksheet
Loop
Do Until "jMe8vpVs4psdIeCAKOPf" <> "UmjO3tHNTZEJSj72Z"
Dim VJ4XtJ_YsQgeEI152k7mN As CheckBox
Dim BfFXbigJhhIjxDUFkajzHajsMONNZ9_NJPHVPTqY1 As Worksheet
Loop
Do Until "hr9UeTv" <> "iu9dB"
Dim X6i6WILTRsih5Xg58yOtJ8jsjVr4 As CheckBox
Dim aoo9dKvTiZ3JdDhx As Worksheet
Loop
Do Until "GZZEw1j5st1YUzT_aQ2lDjCrlLUg" <> "OEYujI6lEiDsNtTU9"
Dim r_2rKJ5tgWqbjeC9ndt9iNJDyJRgSTQWPLlaDUC5c_BvMHeDA As CheckBox
Dim tjOiUXc4w3_2VZKESKV3k5QZyeiKXyooMfhsAw4xGfOaCB As Worksheet
Loop
Do Until "Ehzp46GIYyRytzxPe8MSmz1bDfQht" <> "DnzWvX_Ur"
Dim rfDFsZKCC91_PMrXOqWkVniYTIaa7ax4wCdvirGA1cMh2CVknWG As CheckBox
Dim R8EgC7nvh8tEjJ7LMr5yf As Worksheet
Loop
Do Until "hUs3ZAfPvzvhSd" <> "qdZy46hBFVlV5zH"
Dim rhjslUnl6GduG7fPpAdsQE4j_SlewmjYm7 As CheckBox
Dim D_rtRUzw3vZv3HzUp4UYjln_sQrGyQf_GJ3fg6qH2cKGHLYboZ7pDMUZ As Worksheet
Loop
Do Until "Ur__lr8jNUnrORwtKKfFZezf2NaWT" <> "z_4ybJy5pfIdj2vhqLUmKc2pM_"
Dim y2cGVOiOXUt2vG8xdoVkymC8 As CheckBox
Dim IBEtGUGLjaU7ahH45TcZwxYMoV9LSkJJxd7TIyFBMfPTvAV6ebpcIlIU As Worksheet
Loop
Do Until "k2_tV439PIG6jxs_MZL" <> "Pf_Z"
Dim m_Cqz4p_JTksQtUoRmQCk2YTprkNsY3xeZZtSLBDiH7k9_aS2u3mN As CheckBox
Dim Ayujr_GRZPuawLzSjU_jMca5xTjOPV8eNidkoIkK3tG2KHK As Worksheet
Loop
Do Until "k_PXxB_gVyuVY2BDRNKMrNmZ" <> "t2pcTisnHrnO_hpLh7MyWM"
Dim vArCh678IUUyn6UfKvEFLpMu8tg9ntAxCe_ As CheckBox
Dim ouPAvqJhQ4N3t1BtZrOAEw6_wW7RXTgvHzou4uSYBG5 As Worksheet
Loop
Do Until "r1vGl_i_vd91xKLWs2I7Ubt4" <> "JOznXz882_U6kyoXta"
Dim m1x7qh5pI77dOE27UH4p6e_9rzOv3KtL3cECVRGEbIx_ As CheckBox
Dim iEzs2SNyuCGz As Worksheet
Loop
End Sub
Attribute VB_Name = "Sheet1"
Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Attribute VB_Name = "Sheet2"
Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Attribute VB_Name = "Sheet3"
Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Attribute VB_Name = "LkRU"
Dim EpE7mhAi8HCBEdaBvY1bVfvqL7yoN4xM_aYCQC9JouKLLbNZ3x_I2HPh4XtorUTCSyAm_WtsYovjSidtrXvY3nU1JzG3RSaSZH2VZjTdDPtKUoNT496Sh5HocIbNO1Z_LaIIpFRGCQTl4Hdej As String
Function xM1RHv8Ltkv9xjBAxLvp__HtYBA1eVGY8Kg_(t3blp4siCO1yqfXSBSXZRhaoi_sA14QIf5fQjmUuUwyDo6SBpphAnK_JZwCkIqqG7qRu_ErX8l_esW_ltqTJUOdT5T1wiskm)
Do Until "CeTm5N3IL3lGtF5ahTCX6nw" <> "xtSxJneyZ"
Dim NkodCE1S3sQTpKgovTVs_RXqe As CheckBox
Dim kZreqDJOdeN6dMKDC5dcCFPd2Iapv6K79IdYkWAMHYpAYyzHg_ObLBycHLl As Worksheet
Loop
Do Until "gkdch" <> "RP7Srubn"
Dim PSmYN_BRRHupst6TAOWtcln6FrG2fZugjg5qKC4Gj As CheckBox
Dim MQTq2hf_8pdD3YnopQf6Hv2VM_ As Worksheet
Loop
Dim I_Knp9wL1bi3__7xjXSW_fpauLUERF2emLIOPKDPCp_V2SfvAi_AkUClS
Do Until "JxNH7UOI" <> "OSS"
Dim MNHk1gsPbq
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.