Example report

Remittance-Advice-2026-08.docm

product
Microsoft Word macro-enabled document
vendor
Not established
source
Cloud storage connector, shared drive
assayed
2026-08-05 11:22:41Z
duration
25s
Lens

Or define your ownSection membership is configurable. These three are starting points.

Showing 3 of 18 sectionsShowing 11 of 18 sectionsShowing 18 of 18 sections

Summary readings for this artifact
block8/ 100F12 / 100not established
verdictfile trustvendor riskattribution
confidence high, risk high5 weighted factorsidentity not establishedno identity established

Verdict

The macro source stored in this document does not match the compiled code that would execute. Both are present, both were extracted, and they describe different programs. That mismatch has no legitimate cause and is the entire basis for this verdict.

Key findings

  • VBA stomping detected. The readable source describes a date-formatting routine. The compiled p-code alongside it does not implement that routine, and the two were extracted from the same module in the same pass.
  • An automatic entry point is present. The module runs on open without user interaction beyond enabling content, so the divergence is not academic.
  • Any tool that reads only the stored source sees a document that formats dates. The source is not merely misleading: it was written to be read instead of the code that runs.
  • Document metadata claims an author and organisation with no corroboration anywhere in the file. Treated as an unauthenticated string and given no weight.

Recommended actions

  1. ImmediatelyBlock this hash and quarantine any copies. The verdict rests on a structural property of the file, not on a reputation signal that might change.
  2. ImmediatelyEstablish how it arrived and who has opened it. The extracted observables below give you the search terms.
  3. Follow-upCheck the shared drive for siblings. Stomped documents rarely arrive alone, and similarity clustering against your own history is the cheapest way to find them.
  4. PolicyIf macro-enabled documents from outside the organisation have a business case, scope it narrowly. If they do not, this file is an argument for blocking the class.
Decision4Why it concluded that, and whether to approve

Verdict factors

factorreadingweightdetail
Source and p-code agreementattentionhighThe two representations of the same module describe different programs. Structural, reproducible, and not a matter of interpretation.
Automatic executionattentionhighAn auto-run entry point is present, so the divergence executes rather than sitting inert.
Malicious signalsattentionhighRule matches on obfuscation patterns within the recovered p-code.
Publisher identityneutralmediumUnsigned, and document metadata is an unauthenticated string. No identity established, and none claimed here.
Document categoryneutralmediumMacro-enabled document from outside the organisation. Elevated baseline by category.
Terms-of-service postureneutrallowNot applicable.

Scores

8/ 100 file trust

dimensionweightscorenote
Malicious signals40%0Stomping plus obfuscation in recovered p-code
Code signing20%0Unsigned; no VBA project signature
Vendor reputation20%20No identity established to attach reputation to
Software category15%20External macro-enabled document
Terms-of-service posture5%50Not applicable
Vendor2Who published this, and what corroborates it

Vendor intelligence

F12 / 100 vendor risk · identity estimated · evidence completeness 11%

Identity confidence is graded, not asserted. Every line below is tied to something in the artifact itself: a certificate subject, a declared product string, because a package name is not a vendor.

dimensionweightscorenote
Identity verification25%0Metadata strings only, contradicted by the file itself
Security posture25%0No identifiable publisher
Code signing15%0Unsigned
Licence compliance15%40Not applicable to a document
Community health10%0Not applicable
Vendor maturity10%0No entity to assess

No identity is established and none is claimed. Where the unsigned binary had three unauthenticated properties agreeing with one another, this document has metadata contradicted by its own structure, which is worse than absent evidence, because a name that disagrees with the artifact is a reason to trust the artifact less, not a weaker reason to trust the name.

Evidence

sourcetied tosays
Document metadataAuthor and Company fields inside the fileStrings naming an organisation, with nothing in the file corroborating them
VBA project signatureThe macro project itselfAbsent: the project is unsigned
Creating applicationApplication string in document propertiesInconsistent with the OOXML structure actually present

Enterprise readiness

Deployment methodNot applicable (document)
Macro projectPresent, unsigned
Automatic executionYes, runs on open once content is enabled
External referencesNone in the document body
Embedded objectsNone
Protected view bypassNone attempted
OriginOutside the organisation

Approval readiness

Block

Conditions

  • Hash blocked and copies quarantined
  • Arrival path and open history established
  • Shared drive checked for related documents

Rules matched

No malicious signalsblock
Macro-enabled document from outside the organisationreview
Signed by verified publisherreview
Minimum trust score ≥ 70block
Compliance3Framework posture, obligations, and the limits

Compliance

frameworkmetgapreview
NIST SP 800-53231
SOC 2121
ISO 27001:2022 A.8221
CMMC 2.0121
PCI-DSS v4.0111
HIPAA Security Rule110
GDPR101

Controls

controlstatusnote
SI-3Malicious code protectionNIST SP 800-53gapContent reached a user-accessible location before analysis
SI-7Software integrityNIST SP 800-53gapThe document’s own representations of its code are inconsistent
SC-18Mobile codeNIST SP 800-53gapAuto-executing macro content from an external origin
AC-4Information flow enforcementNIST SP 800-53reviewArrival path through a shared drive needs establishing
CC6.8Unauthorised softwareSOC 2gapExecutable content present in a document store
A.8.7Protection against malwareISO 27001:2022 A.8gapDetected at analysis rather than at ingress

Licence obligations

Not applicable. A document carries no licence terms of its own.

obligationappliesnote
Commercial-use restrictionnoNot applicable
AttributionnoNot applicable
CopyleftnoNot applicable
Source disclosurenoNot applicable
Patent grantnoNot applicable

Analysis coverage

What was examined, and what was not. The limits belong next to the decision, not behind it.

Examined

OOXML package structure and every part within itfull
VBA project, stored source, decompressedfull
VBA project, compiled p-code streamfull
Comparison between the two, which is where the finding isfull
Document properties and relationshipsfull
Rule matching across extracted contentfull

Not examined

Advisory and vulnerability statusNot assessed. This report describes what the file is and who made it, not what is known to be wrong with the software.
Runtime behaviourStatic analysis only. The macro was never executed, and nothing here describes what happens if it is.
Network destinations contacted at runtimeWould require execution. The observables below are strings recovered from the file, not connections observed.
Multi-engine antivirus verdictsMulti-engine antivirus runs on a customer-supplied key by design: the quota and the data-sharing decision stay with you rather than with us. No key is attached to this example, so no engines were consulted.
Composition4What it is made of, and what identifies it

File overview

TypeMicrosoft Word 2007+ document, macro-enabled (OOXML)
FamilyOffice document
Size284 KB
Submitted2026-08-05T11:22:16Z
Completed2026-08-05T11:22:41Z

File identifiers

SHA-256d41b8f0a37c692e584b0179ac35fe2d6018b47c93a5e60f24db8137ea0c9f5b6
SHA-19a3f61b04e7c25d8130af6b92e04c7185da3e0f1
MD56b09e2fa17c4d385021ba7e94f3c60d8
TLSHT1C82E5B37A0D94F16C35E0728BD64A19F3C05E86D2A47B901FE35C6D08B472AE19D30F5

Names

Submitted asRemittance-Advice-2026-08.docm
Title propertyRemittance Advice
Author propertyUnauthenticated string
Company propertyUnauthenticated string

Nearest in your own history

artifacttlsh distanceseen
Payment-Confirmation-2026-07.docm182026-07-29
Remittance-Advice-2026-07.docm242026-07-02

Two close matches in this tenant’s own history, both macro-enabled documents on the same shared drive. A distance under 30 indicates shared construction rather than shared subject matter. This is the finding to act on after the block.

Technical details

ContainerOOXML (ZIP)
Parts14
Macro projectword/vbaProject.bin
VBA modules2
Project signatureAbsent
Created2026-08-04T22:07:11Z (document property, unauthenticated)
Modified2026-08-04T22:09:38Z (document property, unauthenticated)
Creating applicationDeclared string inconsistent with the structure present

Sections

namecharacteristicsentropynote
word/document.xmlDocument body5.12Two paragraphs of ordinary invoice text
word/vbaProject.binOLE compound file, macro project7.41High entropy relative to the rest of the package
word/vbaProject.bin :: PROJECTStored source stream4.88The version every source reader sees
word/vbaProject.bin :: _VBA_PROJECTCompiled p-code stream7.63The version that executes
docProps/core.xmlDocument properties4.21

Signature

Document signatureAbsent
VBA project signatureAbsent
ConsequenceNothing in the file attests to its origin. The metadata naming an author is a string a user typed, not a claim anyone stands behind.

Enrichment

sourceconsultedresult
Known-malware hash intelligenceyesNo record for this hashAbsence of a record is not evidence of safety, and this verdict does not depend on it. The finding is structural.
Community threat-intelligence pulsesyesNo pulses reference this artifactNever sufficient on its own: a single uncorroborated feed does not drive a verdict in either direction, and none drove this one.
Certificate transparencynoNot applicableNo certificate present.
Company registrationnoNot applicableNo verified organisation name to look up. The metadata string is not treated as one.
Licence resolutionnoNot applicable
Multi-engine antivirusnoNot consultedMulti-engine antivirus runs on your own vendor key by design: your quota, your data-sharing terms, not ours. That is a deliberate product decision rather than a limitation. No key is attached to this example, so no engines were consulted and no engine result appears anywhere in this report.

Extracted macrosnot shipped

Source extraction and stomping detection are real. Recovering intent from compiled p-code is partial: the divergence is detected reliably, the reconstruction of what the p-code does is best-effort.

Everything below was extracted from the document and is displayed as inert text. It is not executable here, it was not executed during analysis, and no part of this page runs it. It is shown because reading it is the point.

Module1source and p-code agree

Stored source: what a reader sees

' Formats invoice dates for the remittance table
Public Sub FormatDates()
    Dim c As Range
    For Each c In ActiveDocument.Range.Cells
        If IsDate(c.Range.Text) Then
            c.Range.Text = Format(CDate(c.Range.Text), "dd mmm yyyy")
        End If
    Next c
End Sub

Compiled p-code: what would execute

Matches the stored source. This module is what it says it is, and it is included so the comparison below has a control.

ThisDocumentruns on opensource and p-code disagree

Stored source: what a reader sees

' Applies house formatting on open
Private Sub Document_Open()
    Application.ScreenUpdating = True
    FormatDates
End Sub

Compiled p-code: what would execute

Does not match. The recovered p-code for this module contains string-concatenation and character-code arithmetic that assemble a command line at runtime, followed by a call through a shell interface. Nothing resembling FormatDates appears in the compiled stream, and nothing resembling the compiled stream appears in the stored source.

Stored source and compiled p-code describe different programs

Word executes the compiled p-code and ignores the stored source when the compiled version targets the running Office release. The stored source exists to be read. Replacing it while leaving the p-code intact is what stomping is, and it defeats every tool that inspects macro source without also decompiling.

This is the clearest case on the site for reading a file rather than looking it up. There is no name to query, no hash to recognise, no publisher to check. The finding exists only because both representations were extracted and compared, and it would survive the document being renamed, re-saved, or sent from a different address.

Forensics2What it touches, and when

Indicators and behaviournot shipped

ATT&CK technique mapping and D3FEND pairing are designed here at a depth the current pipeline does not reach. Observable extraction is real; the mapping from observable to technique is partly manual today.

Observables

typevaluecontext
String fragmentChr(104) & Chr(116) & Chr(116) & Chr(112)Character-code assembly in recovered p-code
InterfaceWScript.ShellLate-bound object reference in recovered p-code
Entry pointDocument_OpenAutomatic execution on open
FilenamePayment-Confirmation-2026-07.docmNear neighbour in this tenant’s own history

Techniques

techniquewhy it is listedcountermeasure
T1566.001Phishing: Spearphishing AttachmentMacro-enabled document with an invoice pretext, arriving from outside the organisation.Message and attachment analysis at ingress
T1204.002User Execution: Malicious FileExecution requires a user to enable content, which is the only control standing between arrival and execution.Macro execution policy
T1027Obfuscated Files or InformationCharacter-code arithmetic assembling strings at runtime, plus the source and p-code divergence itself.Static content analysis
T1059.005Command and Scripting Interpreter: Visual BasicThe executing code is VBA reaching a shell interface.Script execution logging

Unlike the other examples on this site, these techniques describe intent rather than merely capability. The distinction is the divergence: an installer that creates a service is doing its job, and a document whose readable source disagrees with its compiled code is not.

Timelinenot shipped

Reconstructed from artifact timestamps and analysis events. Ordering across sources is best-effort, clock skew between a build host and an analysis host is not resolved.

wheneventfromconfidence
2026-08-04T22:07:11ZDocument createdDocument property, asserted by the file, unverifiable
2026-08-04T22:09:38ZDocument last modifiedDocument property, asserted by the file, unverifiable
2026-07-29T00:00:00ZNear-identical document analysed in this tenantSimilarity history
2026-08-05T11:22:16ZCollected from shared driveCloud storage connector
2026-08-05T11:22:41ZAnalysis completedAnalysis record

Confidence is struck as fineness, the same unit the register uses. Verified means the timestamp is signed or recorded by us; estimated means it is asserted by the artifact and unverifiable.

More of this

New posts on what a file tells you before you run it: headers, signatures, manifests, overlays, the fields most inventory never reads. Only when there is something worth the write-up.

We intend to offer a tool that does this across every file on an endpoint. You get one message when you can use it.

One field, any address. Those two things and nothing else, and replying to any of it removes you.