Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 6d39af51574dd2a9…

MALICIOUS

Office (OLE) / .DOC

35.5 KB Created: 2018-05-15 15:35:00 Authoring application: Microsoft Office Word
MD5: 7880a00abc10f77aa62d495939321302 SHA-1: 0879953239f2f85ba0ec439d52a99f52bff29f66 SHA-256: 6d39af51574dd2a9d3603d1efe692400070fb06afce3870d06bb4005d940153e
342 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File T1105 Ingress Tool Transfer

The file contains VBA macros that utilize Shell() and CreateObject() functions, indicative of malicious intent. Specifically, the macros are designed to download and save a file to disk using HTTP, which is a common technique for delivering second-stage payloads. The ClamAV detection further supports its malicious classification.

Heuristics 8

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • VBA downloads and writes a file to disk critical OLE_VBA_HTTP_DROP_EXEC
    VBA reads an HTTP response body and writes it to disk (ADODB.Stream SaveToFile). Combined with the auto-exec/Shell paths this is a download-drop dropper even when the COM ProgIDs are built dynamically to evade keyword scanning.
  • ClamAV: Doc.Downloader.00536d-6923444-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.00536d-6923444-0
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
8c7dce294e98eea6f32b108b60657aa238b973e7ca538060da2c96be1ae99487
vba-macro oletools.olevba.extract_macros (decoded VBA source) 4864 bytes