LetsDefend : SOC205 — Malicious Macro has been executed
Trigger Reason : Suspicious file detected on system.
LetsDefend :
SOC205 — Malicious Macro has been executed

Malicious Macro has been executed
EventID : 231
Event Time : Feb, 28, 2024, 08:42 AM
Rule : SOC205 - Malicious Macro has been executed
Level : Security Analyst
Hostname : Jayne
Ip Address : 172.16.17.198
File Name : edit1-invoice.docm
File Path : C:\Users\LetsDefend\Downloads\edit1-invoice.docm
File Hash : 1a819d18c9a9de4f81829c4cd55a17f767443c22f9b30ca953866827e5d96fb0
Trigger Reason : Suspicious file detected on system.
AV/EDR Action : Detected
Analyse
The file has the extension .docm, which indicates a macro-enabled Word document.
File Hash
We verified the file hash on VirusTotal

VirusTotal
The macro was flagged as malicious. Additional context is available in the Code Insights results.
The document contains a macro in
ThisDocument.clsthat triggers when the InkEdit control namedGBjdshuiKJreceives focus. TheInkEdit1_GotFocussubroutine executes a shell command. The command to be executed is retrieved from theTextBox1control located onUserForm1. The shell command is executed with the window style set to 0, which corresponds to a hidden window. This means that upon gaining focus, the InkEdit control will execute a command retrieved from a textbox on a user form, without displaying a window.
Endpoint Security
We have to isolate the infect host in Endpoint Security.
Hostname: Jayne
Ip Adress: 172.16.17.198

Containment
To continue the analysis, we will examine how Jayne obtained the malware.


phishing
Preliminary email analysis indicates a phishing message originating from phishingjake.admin[at]cybercommunity[.]info sent to jayne[at]letsdefend[.]io.
Log Management

Log Management
- 08:41 AM : A ZIP containing the malicious document was placed in Downloads
- 08:42 AM : User opens the Document
- 08:42 AM : Macro execute PowerShell and execute the download of the remote ressource at hxxp[:]//www[.]greyhathacker[.]net/tools/messbox[.]exe
- 08:42 AM : PowerShell caused a DNS lookup for the C2 host (92.204.221[.]16)
- 08:42 AM : PowerShell script block execution recorded
Case Management

Incident Details
-
Defined Threat Indicator : Other
-
Quarantined : No
-
Analyze Malware : Malicious
-
C2 : Accessed
-
Add Artifacts

- Analyse note
On Feb 28, 2024 at 08:42 AM, a user on host Jayne (172.16.17.198) opened a malicious macro-enabled Word document (edit1-invoice.docm). The macro executed a PowerShell command that attempted to download a remote executable from www[.]greyhathacker[.]net (92.204.221[.]16). The activity was captured by Sysmon and endpoint logs, including DNS queries and script block execution.
Prior to this, at 08:12 AM, a phishing email from jake.admin[@]cybercommunity[.]info was sent to Jayne, containing the malicious document.
This incident represents a high-severity security event, as it allowed the download and potential execution of malware. Immediate actions taken included host isolation, preservation of artifacts, and defanging of IOCs for reporting.
Close Alert
True Positive
Host isolated and email deleted. 메타데이터
- post_id
- e10411481ffd
- slug
- letsdefend-soc205-malicious-macro-has-been-executed-e10411481ffd
- url
- https://medium.com/@4th3n4x/letsdefend-soc205-malicious-macro-has-been-executed-e10411481ffd
- canonical_url
- https://medium.com/@4th3n4x/letsdefend-soc205-malicious-macro-has-been-executed-e10411481ffd
- author_url
- https://medium.com/@4th3n4x
- status
- ok
- fetched_at
- 2026-06-16 19:09:56