Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 8e2b17f258966d7c…

MALICIOUS

Office (OOXML) / .DOC

100.9 KB Created: 2021-04-28 05:09:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: d658fc2e8c2b71b78799247a60255ff8 SHA-1: feefaee757769c0f2823c0038b7a17ce63f27522 SHA-256: 8e2b17f258966d7c4af9d20dd17dc0a20dc2c0c2fa54fd41c8afa98a95857246
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1204.002 Malicious File

The OOXML document contains VBA macros, specifically an AutoOpen macro, which is designed to execute automatically when the document is opened. The heuristics indicate the presence of a CreateObject call and a suspicious extracted artifact containing encoded blobs and script execution terms. This suggests the macro is intended to download and execute a second-stage payload from the provided URL. The document body itself does not contain user-facing text, indicating its primary purpose is to deliver the malicious macro.

Heuristics 5

  • AutoOpen macro high OLE_VBA_AUTOOPEN
    AutoOpen macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://shepard2018-transport.com/bijol/Aobi0ALLez0HkzJ3Tiik2YxtlkOXUyWLjphkF5FE/rc4htVOK5jSU7jR/pPImzpiKfGsVqfUgAbSAF64f95I51JxrJ8KafT4A25Hz5/sQGl4hMo
    • http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
d3a3b61d2af02b7878b28ada19135d89e8924918c6052548aece0a65ac090af1
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 2881 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
079b5cbaf8e1de3aa8eaf65c6518e996e69665e585b487335ac1822ceeff5293
vba-project OOXML VBA project: word/vbaProject.bin 27648 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 1 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.