Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 ab8023d2e9ab8793…

MALICIOUS

Office (OOXML) / .XLSX

231.9 KB Created: 2021-08-05 09:18:28 UTC Authoring application: Microsoft Excel 16.0300
MD5: 883153b68335d2a6b3956ae967f38641 SHA-1: 6c0f3f6088544f07c5cc0c6e4c8a7b54376740e4 SHA-256: ab8023d2e9ab87937b572bb2e136c6003181b6745746d06e6e289e0f22e9f0c5
260 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1059.003 Windows Command Shell T1071.001 Web Protocols T1105 Ingress Tool Transfer

The sample is a macro-enabled Excel spreadsheet that contains a Workbook_Open macro. This macro calls a subroutine that reconstructs a URL from obfuscated string concatenations, specifically "http://www.example.com/payload.exe". It then uses WScript.Shell to execute a command, likely to download and run the payload from the constructed URL. Persistence is established via a Run-key write to HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAccessible2Proxy.

Heuristics 6

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
5f05cb43536b96136f140e9dbb141e5215f429c19ed17a884641703796dbb398
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 4906 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 4 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
afee98769f64a2ccf7b0936305eb637d2b1f0336d1704efa4fc177b418b7d9bf
vba-project OOXML VBA project: xl/vbaProject.bin 36864 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 5 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.