Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 b75af3709a1cb064…

MALICIOUS

Office (OOXML) / .DOC

50.6 KB Created: 2021-06-28 10:47:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: 10ce955f1590a209fb838511200dc2e9 SHA-1: bb440bc23f50927bbe3ddd41662d93d37009d3cc SHA-256: b75af3709a1cb0645ae7555d9f36305ecec8d5c1816986c1dd0f48ea3e26441c
262 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1059.003 Scheduled Task/Job T1566.001 Valid Accounts T1071.001 Application Layer Protocol – Web Protocols T1071.002 Web Service Scripts

The file exhibits several characteristics indicative of a malicious macro-based downloader. The presence of VBA code, specifically the `Document_Open` macro, coupled with `Shell()` calls and references to `cmd.exe` strongly suggests an attempt to execute arbitrary commands or download a secondary payload. The ClamAV detection further confirms this suspicion. The embedded URLs, while benign in themselves, are likely used to trigger the malicious behavior. The obfuscated VBA code and the use of `indexDocTmp` function are typical techniques employed to evade detection.

Heuristics 7

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • ClamAV: Doc.Downloader.Ursnif06210-9875010-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Ursnif06210-9875010-0
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • cmd.exe reference in VBA high OLE_VBA_CMD
    cmd.exe reference in VBA
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
59df1f82cfabfaf2435e15a649680920127fb9d794ce5278baa622f42f7f778a
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1380 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
8a76a7eb2873b3854f0f197679f01499ec2d5f5a0f12538ca7e1f73b953b3962
vba-project OOXML VBA project: word/vbaProject.bin 17920 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.