MALICIOUS
82
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1566.001 Spearphishing Attachment
The sample is a Microsoft Word document with a large VBA macro. Heuristics indicate the presence of VBA macros and a critical ClamAV detection for 'Doc.Malware.Valyria-10035018-0'. While the VBA code is truncated, the presence of API calls like HeapCreate and HeapAlloc suggests memory manipulation, often used to download and execute payloads. The embedded URL was confirmed benign, and no other IOCs were extracted.
Heuristics 3
-
ClamAV: Doc.Malware.Valyria-10035018-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Malware.Valyria-10035018-0
-
VBA macros detected medium OLE_VBA_MACROSDocument contains VBA macro code
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas19823524f280b476707c871cd73100ac3d2d159841040b649a737cc9b52d342e |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 931844 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.