Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 47e220844a72c258…

MALICIOUS

Office (OOXML) / .XLSM

45.6 KB
MD5: f0f9db883404ca28dec9a0f2212a01d7 SHA-1: a7086a134b92b414e97a3c3ea23237b563af8737 SHA-256: 47e220844a72c2582edc5c8496b3fca49729cf8d30e86f535db795270e7f364a
220 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The document contains VBA macros that utilize PowerShell to download a file from 'stpatricksresidences.cos.sg//Client.exe' and save it as 'C:\Users\Public\Documents\omsmyrlyj.exe', which is then executed. This indicates a downloader or droppper functionality. ClamAV also detected this file as Xls.Malware.Sagent-10035294-0.

Heuristics 5

  • ClamAV: Xls.Malware.Sagent-10035294-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sagent-10035294-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
23fafc81a9d418d1ba800ec23e8044c6c82f79b56f29be976b4c016eda8f6e86
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 2248 bytes
vbaProject_00.bin
18a86fea025690ddece05c079827305af6a43c4cb58c4e6b3bea13b4650e5a75
vba-project OOXML VBA project: xl/vbaProject.bin 5632 bytes
Detection
ClamAV: Xls.Malware.Sagent-10035294-0
Obfuscation or payload: unlikely