Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 b4f8da4dadd6a3f1…

MALICIOUS

Office (OOXML) / .DOC

44.6 KB Created: 2021-06-08 10:40:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: 099143069f49484c68a053877ecea389 SHA-1: 660d36230c547c3d7407de25fbe7b170e0a08380 SHA-256: b4f8da4dadd6a3f18b98cd39b3d6202d0afcc46db01fbcf792daf0cd36dbd85c
262 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.003 Windows Command Shell T1204.002 Malicious File

The sample is a malicious OOXML document containing a VBA macro. The AutoOpen macro, along with critical heuristic firings for Shell() and WScript.Shell usage, indicate that the macro is designed to execute arbitrary commands. The specific commands executed are not detailed in the provided evidence, but the overall pattern suggests a downloader or initial access mechanism.

Heuristics 7

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • AutoOpen macro high OLE_VBA_AUTOOPEN
    AutoOpen macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://breezebishopd.com/adda/o632aWWcVINA1TIqiriq/DPf2kk7ws9xfD1RHVaUPXh37NB7w3QtwOeV5GsQGJ/5982/TVki0hOvRtdgFkuc9d6nvY1ptWIo/paxi1?cid=CmP3J1Gpjfb6BUjHjlxjFoOwmpDp&sid=Bebdaj7qIDp2jpS1AmQRCHcvZ8fqO&ref=FImtFMC2nQWLU6cCQhJ
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
c6c5b5c5dcb735b14cbe2d6ab4f746f7278af53a5990aaa829d47064b8bef092
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1109 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
7cfc51559796b22054dc513d687f23c603ad5d14e72806ad1094c768ecb7e7c4
vba-project OOXML VBA project: word/vbaProject.bin 13824 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved macro source contains an auto-exec entry point and execution/download terms.