Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 3c8dc1c17fa800da…

MALICIOUS

Office (OOXML)

20.6 KB Created: 2021-07-11 09:14:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: 3ac5b80ba2a42f4b1f1f93c36e1a5934 SHA-1: 221fd9144c7fcadb7319a90d89d760e8ab30b2b8 SHA-256: 3c8dc1c17fa800da8caace53dc8249b4c7e100b70fa63f8bd18bd43b439dabb2
182 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is an OOXML document containing a VBA project with an AutoOpen macro, indicating malicious intent. The presence of VBA code, specifically the AutoOpen function, suggests it's designed for immediate execution upon opening. ClamAV detections further confirm its malicious nature, classifying it as Doc.Malware.Valyria-10015188-0. The VBA code appears to be involved in process manipulation and potentially downloading further payloads, though the exact execution path is truncated.

Heuristics 5

  • ClamAV: Doc.Malware.Valyria-10015188-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Malware.Valyria-10015188-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • AutoOpen macro high OLE_VBA_AUTOOPEN
    AutoOpen macro
  • VBA project inside OOXML medium OOXML_VBA
    Document contains a VBA project — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.microsoft.com/office/drawing/2015/10/21/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/9/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/10/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/11/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/12/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/13/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/14/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.microsoft.com/office/drawing/2016/ink
    • http://schemas.microsoft.com/office/drawing/2017/model3d
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2018/wordml/cex
    • http://schemas.microsoft.com/office/word/2016/wordml/cid
    • http://schemas.microsoft.com/office/word/2018/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
8335304fd558be66ab5485d1b153908c6fc0d8f93c28ff9ff91cbe5312c8746e
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 4523 bytes
vbaProject_00.bin
5618e44ee41256bae601cdbda6edb1f1c9330a6e857e7dafe071d08ac204b535
vba-project OOXML VBA project: word/vbaProject.bin 21504 bytes
Detection
ClamAV: Doc.Malware.Valyria-10015188-0
Obfuscation or payload: unlikely