MALICIOUS
310
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1204.002 Malicious File
T1566.001 Spearphishing Attachment
T1071.001 Web Protocols
The document contains a lure instructing the user to enable macros, which is a common tactic for malware delivery. The AutoOpen VBA macro is triggered upon opening, and it utilizes the Shell() function to execute commands. The script also contains a commented-out URL that likely points to a malicious payload, and the presence of 'curl' in the document body suggests an attempt to download external content. The macro's intent is to download and execute a second-stage payload.
Heuristics 10
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
Reference to Windows Script Host high SC_STR_WSCRIPTReference to Windows Script Host
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
CreateObject call high OLE_VBA_CREATEOBJCreateObject call
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
VBA macros detected medium OLE_VBA_MACROSDocument contains VBA macro code
-
Macro/content-enable lure medium SE_ENABLE_LUREDocument instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings
-
Environ() call (env variable access) low OLE_VBA_ENVIRONEnviron() call (env variable access)
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://www.virsec.de/img/mcafee-rgr.png
- https://dashdot.de/wp-content/uploads/2018/12/Windows-Logo.jpg
- https://www.incimages.com/uploaded_files/image/1920x1080/getty_168325476_349217.jpg
- https://www.mindsetters.com
- https://uploads-ssl.webflow.com/6152fffd477fccbd0911a851/61584cc521b13c9a8cac5796_mindsetters_circle.png
- http://schemas.openxmlformats.org/drawingml/2006/main
- http://schemas.openxmlformats.org/officeDocument/2006/bibliography
- http://schemas.openxmlformats.org/officeDocument/2006/customXml
- http://schemas.microsoft.com/sharepoint/v3/contenttype/forms
- https://workbench.redbull.com/departments/information-technology/services/digital-security/tips-to-stay-secure/phishing/
- http://ec2-34-255-85-35.eu-west-1.compute.amazonaws.com/api/rbuser
- https://sharevideo.redbull.com/vjs/index.html?r=1\\&accid=1892432914001\\&pid=EyrSk31Tx\\&vid=6113290091001
- https://sharevideo.redbull.com/vjs/index.html?r=1&accid=1892432914001&pid=EyrSk31Tx&vid=6113290091001
- http://schemas.microsoft.com/office/2006/metadata/contentType
- http://schemas.microsoft.com/office/2006/metadata/properties/metaAttributes
- http://schemas.microsoft.com/office/2006/metadata/properties
- http://www.w3.org/2001/XMLSchema
- http://schemas.microsoft.com/office/2006/documentManagement/types
- http://schemas.microsoft.com/office/infopath/2007/PartnerControls
- http://schemas.openxmlformats.org/package/2006/metadata/core-properties
- http://www.w3.org/2001/XMLSchema-instance
- http://purl.org/dc/elements/1.1/
- http://purl.org/dc/terms/
- http://schemas.microsoft.com/internal/obd
- http://dublincore.org/schemas/xmls/qdc/2003/04/02/dc.xsd
- http://dublincore.org/schemas/xmls/qdc/2003/04/02/dcterms.xsd
- https://sharevideo.redbull.com/vjs/index.html?r=1
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas266ad050f1e7a25e89f9dc12092565822fd421a9ec6737737a685291622edf4b |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 7800 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.