Emotet — Office (OLE) malware analysis

Static analysis result for SHA-256 30b2c0c6efaad4e4…

MALICIOUS

Office (OLE)

68.2 KB Created: 2017-10-10 15:18:00 Authoring application: Microsoft Office Word First seen: 2017-10-28
MD5: 715d3aac742b64a57bbb2456745e9113 SHA-1: a085491ac6aad231ce2a519f15cdc116b2f586a3 SHA-256: 30b2c0c6efaad4e4bab2e679eb8a1261b2c1520c92585582462ef60c97a78864
110 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment

The file was detected as Win.Trojan.Emotet-6397178-0 by ClamAV, strongly indicating the Emotet family. A heuristic firing for PowerShell references suggests the execution of malicious scripts. Although the VBA macros themselves contain no executable statements, the presence of PowerShell references and the Emotet detection point to a malicious document designed to download and execute a second-stage payload.

Heuristics 4

  • ClamAV: Win.Trojan.Emotet-6397178-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Emotet-6397178-0
  • Reference to PowerShell high SC_STR_POWERSHELL
    Reference to PowerShell
  • VBA project contains no executable statements low OLE_VBA_MACROS
    Document contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source) 286 bytes
SHA-256: 7771bf99b1125ee0f87040a7dc7c1fa89eec2186bbf4ab3e822c8d665693af47
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "ThisDocument"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True