Skip to main content
← Back to Demos
Macro beginner · 15 min

Malicious Word Document with AutoOpen VBA Macro

Office documents remain a top malware delivery vector, and VBA macros are among the oldest and most reliable tricks in the trade. A weaponized .docm file hides a malicious AutoOpen routine: the moment the victim enables macros and opens the document, the embedded VBA executes and can download and run further payloads from a remote server. Because the macro code is obfuscated and packed inside the document's binary structure, signature-based scanners often miss it. This demo uses a benign VBA macro that only launches Calculator, so it is completely safe to run. Deep CDR opens the document in a virtual environment, sanitizes the macro content, and reconstructs a clean file that keeps its formatting but carries no executable code — neutralizing the threat before it reaches the end user.

Attack Technique

VBA macro execution

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxmacoswindows

File Types

.odt

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---