Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 5763ab87d3323c8b…

MALICIOUS

Office (OOXML) / .DOC

66.0 KB Created: 2021-05-17 09:12:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: 8e8023bbfa3996bf9165cc2b3b772fdd SHA-1: 44f8eb194cbf7d7953d6b1d62db4d9f0e0979fa7 SHA-256: 5763ab87d3323c8b9a36340b6270756960f9063bc858ed2a09b5f2f5d9618cfe
102 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is a malicious OOXML document containing VBA macros. The presence of a 'Document_Open' macro indicates that malicious code will execute automatically when the document is opened. The 'GetObject' call is often used to load and execute external code. While no specific family is identified, the macro-based execution is a common delivery method for various malware types.

Heuristics 4

  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • GetObject call high OLE_VBA_GETOBJ
    GetObject call
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/photoshop/1.0/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
167334741c1e3f0d4b3ee2610690004ee00006460ad1e270e08d4ecb190f21b2
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1067 bytes
vbaProject_00.bin
b618d15c3b5e18f25c7c95b7a0bd4efa4f7290b5f65ec09a5ba68084271bc5dc
vba-project OOXML VBA project: word/vbaProject.bin 17408 bytes