Macro-bearing document shapes
macro_document_shapes
Writes the document shapes phishing campaigns use — a macro-enabled OOXML package with a vbaProject part, an HTA script, a Windows script file and a shortcut-style command file — each carrying inert test content. None of them is a working document and nothing is opened or executed.
What it needs before it will run
-
runs in --safeObservation only. It runs even in the inert mode, because it changes nothing and sends nothing.
Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.
ATT&CK techniques it exercises
| Technique | Name | Tactic | Across public reports |
|---|---|---|---|
| T1059.005 | Visual Basic | Execution | coverage statistics |
| T1204.002 | Malicious File | Execution | coverage statistics |
| T1566.001 | Spearphishing Attachment | Initial Access | coverage statistics |
How often anything notices
Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.
Other antivirus signatures tests
| Test | What it does | Severity |
|---|---|---|
| EICAR download over HTTPS eicar_download | Fetches the EICAR test file from the official eicar.org endpoints (an AMTSO test resource) to observe whether the download path — proxy, TLS inspectio… | low |
| EICAR test file write eicar_file_write | Writes the standard 68-byte EICAR anti-malware test file into the sandbox and re-checks it for several seconds to catch asynchronous quarantine. | low |
| EICAR variant battery eicar_variant_battery | Writes six on-disk shapes of the EICAR test file (plain, double extension, padded, prefixed, zipped, nested zip) to compare how deeply the scanner ins… | low |
Catalogue generated from client 0.1.0. A test's behaviour can
change between releases; this page describes the version named here.