Emotet — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 40c2598506985a05…

MALICIOUS

Office (OOXML) / .XLSX

115.1 KB Created: 2015-06-05 18:17:20 UTC Authoring application: Microsoft Excel 12.0000
MD5: dc9517a1b2cdbeeeeef82d953cc4ff6c SHA-1: d8912efe671920d1d291b09a5fc29c791b75f4cb SHA-256: 40c2598506985a05f55fd16b1fc5262e40e0da50e0b8caa5d48060a65bb1e28f
200 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1059.005 Visual Basic

The file is detected as Emotet by ClamAV and contains a Workbook_Open macro, indicating an attempt to automatically execute malicious code upon opening. The embedded VBA script utilizes Wscript.Shell to create and execute batch and VBScript files. The batch script contains heavily obfuscated PowerShell commands, including a reconstructed URL: "http://sumedahonline.com/wp-content/HyzNXJ30XQEBSRH/", which is likely used to download a second-stage payload. The presence of these elements strongly suggests a downloader functionality typical of Emotet.

Heuristics 5

  • ClamAV: Xls.Downloader.EmotetExcel02223-9938902-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.EmotetExcel02223-9938902-0
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
df1eb14c222394595c0518b49eec2b55ed9573146c5f1717dedceddd2e199a2b
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 12041 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
61fec236c48fbdd4394bca0147b6404511c03c8ed254a378ef452df7a51863d3
vba-project OOXML VBA project: xl/vbaProject.bin 42496 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.