MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1566.001 Spearphishing Attachment
The sample exhibits characteristics of a legacy macro-based malware, specifically triggering high-severity heuristics for legacy WordBasic macro virus markers and an AutoOpen macro. The presence of VBA macros, combined with the legacy markers, suggests an attempt to execute arbitrary code upon opening the document, likely for malicious purposes such as downloading a secondary payload.
Heuristics 3
-
Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUSOLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.
-
VBA macros detected medium 1 related finding OLE_VBA_MACROSDocument contains VBA macro code
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 17459 bytes |
SHA-256: 0e639c4c15aa5fd19a7369b03138d542d4cfbea3ce098340daa4aa6312710baa |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "Derroche"
Rem KHZUSKTHJLYDQJCECL
Rem XLRNNMJKHBGZBKJMEMGQOE
Rem EQZIGWDOPPS
Rem KHZUSKTHJLYDQJCECL
Rem XLRNNMJKHBGZBKJMEMGQOE
Rem JATVHSKV
Rem CPEYCLHWTHRGCA
Rem EPRCQTULCMOBKDDIZPHKMBLLYHENINKGBQJOWKP
Rem URXWKDYUSKAEENKCHQWMEXJIUFLGWPJKWPYNIWG
Rem EQZIGWDOPPS
Rem HGMGIBMFWPTYIOCQKYCYQJDMFZDAIOXN
Rem CZRAOCCUHBHJHYZKHEEQKK
Rem VRSZIMKSEKOVOLNFQMRXJHHDNFPJWMERTP
Rem DEBSN
Rem KHZUSKTHJLYDQJCECL
Rem MTTKXTCQS
Rem MALHTXVECADJEZWPSDGAVUUILOUOFFJOINLOBOFZ
Rem CKISIUDPYGYCZQPXOG
Rem ONQCSGBHYIQJJIFFLQGRPPCBDGKPHVXNK
Rem OSXV
Rem CDD
Rem NTU
Rem TKMM
Rem GPSGOOZYGVUKQMM
Rem VFYBBUJ
Rem QQGHVVPZXFSZ
Rem MZFJKHNDNZOXRLSBTSMEFI
Rem XLRNNMJKHBGZBKJMEMGQOE
Rem TPPGNUWCOKBLSMKYZPNPCEHADKOOUBKBIPNPIXUO
Rem LVFTXFZZWNQLEQPWJBNBJLHZAQPNASIZHJ
Rem PTSRTGONOHKJZNPMAJDRDFJCQ
Rem QFEPCLXGUJHXQQ
Rem SXFJOJFPQDBQVQLEMZUJMORAQXIDLUJKT
Rem JATVHSKV
Rem NKCULTPVAFBCIDANROVCERLJDSY
Rem PHHUATVSBKWUJZWBYJNTBP
Rem CPEYCLHWTHRGCA
Rem DBSVNUZNBQI
Rem NEHCZHQHWIUEHBMLPAIDITQZVOPEX
Rem EBGTYIRUAUMFPXYQARZAYBHPVBBOIK
Rem EPRCQTULCMOBKDDIZPHKMBLLYHENINKGBQJOWKP
Rem LIBKOTPQUKUSSTEUBGYVFEGYGGSRUT
Rem IKDQCFSN
Rem KISFBXBLTTVFMWVKMJ
Rem KVGR
Rem NHPFCXCQXGYWLMUV
Rem URXWKDYUSKAEENKCHQWMEXJIUFLGWPJKWPYNIWG
Rem EQZIGWDOPPS
Rem HGMGIBMFWPTYIOCQKYCYQJDMFZDAIOXN
Rem CZRAOCCUHBHJHYZKHEEQKK
Rem VRSZIMKSEKOVOLNFQMRXJHHDNFPJWMERTP
Rem DEBSN
Rem KHZUSKTHJLYDQJCECL
Rem MTTKXTCQS
Rem MALHTXVECADJEZWPSDGAVUUILOUOFFJOINLOBOFZ
Rem CKISIUDPYGYCZQPXOG
Rem VKUZGESAISCCHKOIHVIJKVKSRKYQNFPTLXHRXHJA
Rem ONQCSGBHYIQJJIFFLQGRPPCBDGKPHVXNK
Rem LTG
Rem OSXV
Rem CDD
Rem NTU
Rem TKMM
Rem GPSGOOZYGVUKQMM
Rem VFYBBUJ
Rem QQGHVVPZXFSZ
Rem MZFJKHNDNZOXRLSBTSMEFI
Rem XLRNNMJKHBGZBKJMEMGQOE
Rem TPPGNUWCOKBLSMKYZPNPCEHADKOOUBKBIPNPIXUO
Rem LVFTXFZZWNQLEQPWJBNBJLHZAQPNASIZHJ
Rem PTSRTGONOHKJZNPMAJDRDFJCQ
Rem QFEPCLXGUJHXQQ
Rem SXFJOJFPQDBQVQLEMZUJMORAQXIDLUJKT
Rem JATVHSKV
Rem NKCULTPVAFBCIDANROVCERLJDSY
Rem PHHUATVSBKWUJZWBYJNTBP
Rem CPEYCLHWTHRGCA
Rem DBSVNUZNBQI
Rem NEHCZHQHWIUEHBMLPAIDITQZVOPEX
Rem EBGTYIRUAUMFPXYQARZAYBHPVBBOIK
Rem EPRCQTULCMOBKDDIZPHKMBLLYHENINKGBQJOWKP
Rem LIBKOTPQUKUSSTEUBGYVFEGYGGSRUT
Rem IKDQCFSN
Rem KISFBXBLTTVFMWVKMJ
Rem KVGR
Rem NHPFCXCQXGYWLMUV
Rem URXWKDYUSKAEENKCHQWMEXJIUFLGWPJKWPYNIWG
Rem EQZIGWDOPPS
Rem HGMGIBMFWPTYIOCQKYCYQJDMFZDAIOXN
Rem CZRAOCCUHBHJHYZKHEEQKK
Rem VRSZIMKSEKOVOLNFQMRXJHHDNFPJWMERTP
Rem DEBSN
Rem NULZDRSTMZWERHWTKCQCRICQ
Rem MTTKXTCQS
Rem MALHTXVECADJEZWPSDGAVUUILOUOFFJOINLOBOFZ
Rem CKISIUDPYGYCZQPXOG
Rem VKUZGESAISCCHKOIHVIJKVKSRKYQNFPTLXHRXHJA
Rem ONQCSGBHYIQJJIFFLQGRPPCBDGKPHVXNK
Rem LTG
Rem OSXV
Rem CDD
Rem NTU
Rem TKMM
Rem GPSGOOZYGVUKQMM
Rem VFYBBUJ
Rem QQGHVVPZXFSZ
Rem MZFJKHNDNZOXRLSBTSMEFI
Rem DEAEFMRSMISZMEUEEQFVMCSVJESQ
Rem TPPGNUWCOKBLSMKYZPNPCEHADKOOUBKBIPNPIXUO
Rem LVFTXFZZWNQLEQPWJBNBJLHZAQPNASIZHJ
Rem PTSRTGONOHKJZNPMAJDRDFJCQ
Rem QFEPCLXGUJHXQQ
Rem SXFJOJFPQDBQVQLEMZUJMORAQXIDLUJKT
Rem JATVHSKV
Rem NKCULTPVAFBCIDANROVCERLJDSY
Rem PHHUATVSBKWUJZWBYJNTBP
Rem CPEYCLHWTHRGCA
Rem DBSVNUZNBQI
Rem NEHCZHQHWIUEHBMLPAIDITQZVOPEX
Rem EBGTYIRUAUMFPXYQARZAYBHPVBBOIK
Rem MLJBZPHMIVSWFCMDEMVRUBFPZUEPRYNNK
Rem LIBKOTPQUKUSSTEUBGYVFEGYGGSRUT
Rem IKDQCFSN
Rem KISFBXBLTTVFMWVKMJ
Rem KVGR
Rem NHPFCXCQXGYWLMUV
Rem URXWKDYUSKAEENKCHQWMEXJIUFLGWPJKWPYNIWG
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.