MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1059.005 Visual Basic
The VBA macro contains a CreateObject call and references PowerShell, indicating it's designed to execute commands. The script reconstructs a PowerShell command that downloads and executes a VBScript from the URL 'http://ag.mnalbivra.net/admin/predictors.vbs', saving it as 'notepad.vbs' in the temp directory. This is a common downloader pattern.
Heuristics 3
-
Reference to PowerShell high SC_STR_POWERSHELLReference to PowerShell
-
CreateObject call high OLE_VBA_CREATEOBJCreateObject call
-
VBA macros detected medium OLE_VBA_MACROSDocument contains VBA macro code
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.base776137b3516f4935511f7418804b5f5b4b7ac880ea796a614fab03b4b32261c |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 1380 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.