← Back to list

LetsDefend :  SOC205 — Malicious Macro has been executed

Trigger Reason : Suspicious file detected on system.

4th3n4x · 2025-10-08 11:45 · 2 claps · 2.7 min read
#lets-defend #macro #cybersecurity #malware #c2
Open on Medium ↗
Wiki topics: GRW · Growth & Analytics 🔒 · Cybersecurity

LetsDefend :

SOC205 — Malicious Macro has been executed

Malicious Macro has been executed

Malicious Macro has been executed

EventID : 231
Event Time : Feb, 28, 2024, 08:42 AM
Rule : SOC205 - Malicious Macro has been executed
Level : Security Analyst
Hostname : Jayne
Ip Address : 172.16.17.198
File Name : edit1-invoice.docm
File Path : C:\Users\LetsDefend\Downloads\edit1-invoice.docm
File Hash : 1a819d18c9a9de4f81829c4cd55a17f767443c22f9b30ca953866827e5d96fb0
Trigger Reason : Suspicious file detected on system.
AV/EDR Action : Detected

Analyse

The file has the extension .docm, which indicates a macro-enabled Word document.

File Hash

We verified the file hash on VirusTotal

VirusTotal

VirusTotal

The macro was flagged as malicious. Additional context is available in the Code Insights results.

The document contains a macro in ThisDocument.cls that triggers when the InkEdit control named GBjdshuiKJ receives focus. The InkEdit1_GotFocus subroutine executes a shell command. The command to be executed is retrieved from the TextBox1 control located on UserForm1. The shell command is executed with the window style set to 0, which corresponds to a hidden window. This means that upon gaining focus, the InkEdit control will execute a command retrieved from a textbox on a user form, without displaying a window.

Endpoint Security

We have to isolate the infect host in Endpoint Security.

Hostname: Jayne
Ip Adress: 172.16.17.198

Containment

Containment

Email

To continue the analysis, we will examine how Jayne obtained the malware.

Email

Email

phishing

phishing

Preliminary email analysis indicates a phishing message originating from phishingjake.admin[at]cybercommunity[.]info sent to jayne[at]letsdefend[.]io.

Log Management

Log Management

Log Management

  1. 08:41 AM : A ZIP containing the malicious document was placed in Downloads
  2. 08:42 AM : User opens the Document
  3. 08:42 AM : Macro execute PowerShell and execute the download of the remote ressource at hxxp[:]//www[.]greyhathacker[.]net/tools/messbox[.]exe
  4. 08:42 AM : PowerShell caused a DNS lookup for the C2 host (92.204.221[.]16)
  5. 08:42 AM : PowerShell script block execution recorded

Case Management

Incident Details

Incident Details

  1. Defined Threat Indicator : Other

  2. Quarantined : No

  3. Analyze Malware : Malicious

  4. C2 : Accessed

  5. Add Artifacts

  1. Analyse note

On Feb 28, 2024 at 08:42 AM, a user on host Jayne (172.16.17.198) opened a malicious macro-enabled Word document (edit1-invoice.docm). The macro executed a PowerShell command that attempted to download a remote executable from www[.]greyhathacker[.]net (92.204.221[.]16). The activity was captured by Sysmon and endpoint logs, including DNS queries and script block execution.

Prior to this, at 08:12 AM, a phishing email from jake.admin[@]cybercommunity[.]info was sent to Jayne, containing the malicious document.

This incident represents a high-severity security event, as it allowed the download and potential execution of malware. Immediate actions taken included host isolation, preservation of artifacts, and defanging of IOCs for reporting.

Close Alert

True Positive
Host isolated and email deleted.

메타데이터
post_id
e10411481ffd
slug
letsdefend-soc205-malicious-macro-has-been-executed-e10411481ffd
url
https://medium.com/@4th3n4x/letsdefend-soc205-malicious-macro-has-been-executed-e10411481ffd
canonical_url
https://medium.com/@4th3n4x/letsdefend-soc205-malicious-macro-has-been-executed-e10411481ffd
author_url
https://medium.com/@4th3n4x
status
ok
fetched_at
2026-06-16 19:09:56