Malicious Office (OOXML) / .DOCX — malware analysis report

Static analysis result for SHA-256 91e4d8713e64427c…

MALICIOUS

Office (OOXML) / .DOCX

104.3 KB Created: 2020-04-29 11:50:00 UTC Authoring application: Microsoft Office Word 15.0000
MD5: 5d63f5fecb2449483fc875746b193b87 SHA-1: ff8ca5c7c34b6f155573fe1d54f23dbd67575834 SHA-256: 91e4d8713e64427c782179522f33a727849cb2e06209844774894fc0fb80e8ff
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The OOXML document contains VBA macros, specifically a Document_Open macro, which is a common technique for initial execution. The presence of CreateObject calls further indicates the intent to execute arbitrary code. No specific malware family could be identified, and no external URLs or executable artifacts were extracted for further analysis.

Heuristics 5

  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
26115fb3bd96ebcdd786aa9cd67d725dc78ff9d62b0eec310b1484eba0955ad8
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1228 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
fe2a64f1ba05dff3a56f923c14109c442de7a934cc2413b4d2de9940ad81345c
vba-project OOXML VBA project: word/vbaProject.bin 10240 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.