MALICIOUS
80
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
The critical ClamAV heuristic firing indicates this file is recognized as malware. The presence of VBA macros, as flagged by the medium heuristic, suggests a malicious script is embedded within the document. The document body contains heavily obfuscated strings, further supporting the likelihood of malicious code execution. The primary intent appears to be downloading and executing a secondary payload, typical of many malware droppers.
Heuristics 2
-
ClamAV: Win.Malware.Agent-9786449-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Malware.Agent-9786449-0
-
VBA macros detected medium OLE_VBA_MACROSDocument contains VBA macro code
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.basdbefb76d6dc68dcae6dda31b8decb8f5fac099e2fd42385c924b2efebfa5ffa4 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 2018 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.