Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 a46458bc99e81157…

MALICIOUS

Office (OOXML) / .DOC

50.5 KB Created: 2021-06-28 10:46:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: a2ef4175d4d3b10559f1033e3a747733 SHA-1: 312ecf8011cfba126bb00d0a7cb73bc19b2741f4 SHA-256: a46458bc99e81157c17295a038fc599197805c840ecd67ecd662f9a383c8577a
262 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1059.003 Scheduled Task/Job T1566.001 Valid Accounts T1071.001 Application Layer Protocol – Web Protocols T1071.002 Web Service Infection T1071.003 Web Traffic T1105 System Information Discovery

The file exhibits multiple indicators of malicious activity, including the presence of a VBA macro that executes `Shell()` calls and references `cmd.exe`. The ClamAV detection confirms the file is classified as malware. The macro's `Document_Open` subroutine, combined with the `Shell()` calls, strongly suggests a downloader attempting to establish a connection and execute a secondary payload. The obfuscated VBA code further indicates an attempt to evade detection. The URLs extracted from the document body are likely associated with the download and execution of the payload.

Heuristics 7

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • ClamAV: Doc.Downloader.Ursnif06210-9875010-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Ursnif06210-9875010-0
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • cmd.exe reference in VBA high OLE_VBA_CMD
    cmd.exe reference in VBA
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
5ce7bf5646d319d23e16b05c26b378b9c1facc0c48b2c44baaf5c181ab12d5c2
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1402 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
a7e4f17423d5d9ccb8fa3a3080953730e96f6c82de1fe5879f30bbd959d0564c
vba-project OOXML VBA project: word/vbaProject.bin 17408 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.