MALICIOUS
102
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059.001 PowerShell
The file is an OOXML document containing VBA macros, indicated by the 'OOXML_VBA' heuristic. The presence of 'CreateObject' and 'CallByName' calls suggests the macros are designed to execute code. While no specific URLs or commands were extracted, the general pattern points to a macro-based downloader. No document body text was available for further context.
Heuristics 4
-
CreateObject call high OLE_VBA_CREATEOBJCreateObject call
-
CallByName call high OLE_VBA_CALLBYNAMECallByName call
-
VBA project inside OOXML medium OOXML_VBADocument contains vbaProject.bin — VBA macros present
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas9613ba47267e12f62a5761a9ba19038f48d1cfeee53520b91a3918b3f5666645 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source from OOXML) | 3736 bytes |
vbaProject_00.binb4bbc8bf42cabc7c0db1b832e032258ebf370defc20cbd8c06bc6b1d6ad17c76 |
vba-project | OOXML VBA project: xl/vbaProject.bin | 403456 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
emf_00.emf68876e56aa79c46bef012c7f76b67be7f60ac1ae3541e4de92a5eb1f6523aca9 |
ooxml-emf | OOXML EMF part: xl/media/image3.emf | 1272 bytes |
emf_01.emf6ce7fc06cd305466b7862b787314f6986f6ae7ddc903fbea131a8fb7675dd369 |
ooxml-emf | OOXML EMF part: xl/media/image4.emf | 1424316 bytes |
emf_02.emfe7d990a3ec732d717878e5ee2e7fc5e0e00d24882ee2006addf6cd81c24276b8 |
ooxml-emf | OOXML EMF part: xl/media/image2.emf | 2384 bytes |
emf_03.emffe2168f37ae91066015f8990a46acd703eb62227625dfa41455dcd59affd2fab |
ooxml-emf | OOXML EMF part: xl/media/image1.emf | 2296 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.