Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 285943e536fb5f87…

MALICIOUS

Office (OOXML) / .DOC

76.7 KB Created: 2021-03-17 05:37:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: 99826fdb9c99798c9a71181aa7f321d5 SHA-1: 3690c705f2f112cafcc285cef65cbd618131ce39 SHA-256: 285943e536fb5f87c9d241a05310cee0f9cc0847915576f6319dbe4f1e3462c2
260 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.003 Windows Command Shell T1204.002 Malicious File

The sample is an OOXML document containing VBA macros, indicated by the 'OOXML_VBA' heuristic. The presence of an 'AutoOpen' macro and the use of 'Shell()' and 'WScript.Shell' (heuristics 'OLE_VBA_AUTOOPEN', 'OLE_VBA_SHELL', 'OLE_VBA_WSCRIPT') strongly suggest that the macro is designed to execute arbitrary commands. The 'CreateObject' call further supports this, likely for creating objects to facilitate execution or download. The overall intent appears to be downloading and executing a second-stage payload.

Heuristics 7

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • AutoOpen macro high OLE_VBA_AUTOOPEN
    AutoOpen macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
f69c72da9ae5b82af7fe6c51cb7c7cae143bb6dcc9fe5505a913990631772cf1
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 3021 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 1 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
b9ab982ca9f378922ead461cbb332d5c57ac3c0a8af267c02ceeb96b234087b7
vba-project OOXML VBA project: word/vbaProject.bin 30208 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 4 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.