Emotet — Office (OLE) / .DOCX malware analysis

Static analysis result for SHA-256 72b9920e61919b7f…

MALICIOUS

Office (OLE) / .DOCX

197.4 KB Created: 2020-09-24 13:34:00 Authoring application: Microsoft Office Word
MD5: f61ac9be9645ff1dae1fb13c750634aa SHA-1: f2b07466fd8e7ed2cb004df50ba1cdcf016319a5 SHA-256: 72b9920e61919b7fc85e4427fa0bcad4d660a87904174a9f3bc2c7ae664ef434
202 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1140 Deobfuscate/Decode Files or Information

The sample contains a VBA macro that is automatically executed upon opening the document, as indicated by the Document_Open heuristic. The macro employs obfuscation techniques, making it difficult to determine the exact payload, but the presence of CreateObject and the ClamAV detection name 'Doc.Downloader.Emotet' strongly suggest it functions as a downloader for a secondary malicious payload, likely Emotet. The obfuscated VBA code is designed to deobfuscate and execute commands, which is a common tactic for this malware family.

Heuristics 6

  • ClamAV: Doc.Downloader.EmotetRed02224-9938637-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.EmotetRed02224-9938637-0
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
a837a74c15cb3b2b06d70805c30f06a3d350fde6faccbab7be73edc42a69bb80
vba-macro oletools.olevba.extract_macros (decoded VBA source) 25402 bytes