Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 31f39dd77af9d245…

MALICIOUS

Office (OOXML) / .DOC

104.3 KB Created: 2020-06-01 19:33:00 UTC Authoring application: Microsoft Office Word 15.0000
MD5: 6056c72063c08f6b84bd3fd3f82e684c SHA-1: d462b6e2d6edf1687f201ac9348f18a33de81e8b SHA-256: 31f39dd77af9d24596f9e75b563912f1d41145778e42b61bc5a6834124c3f8df
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The OOXML document contains VBA macros, specifically a Document_Open macro, which is a common technique for executing malicious code automatically when the document is opened. The presence of CreateObject calls further indicates an attempt to run arbitrary code. While no specific malicious URLs or payloads were extracted, the macro's presence and auto-execution trigger strongly suggest a malicious intent, likely to download and execute a second-stage payload.

Heuristics 5

  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
d78cd99e38d1dbceca6f7171037866da8a47599ff7143014470fab1ae67453d8
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1920 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
83a521ea9c76ad1c73feceee8701cacc3e8307c19802aae11dec3f6a13059bfe
vba-project OOXML VBA project: word/vbaProject.bin 11776 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.