Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 c3e12a45ab7b3680…

MALICIOUS

Office (OOXML)

41.5 KB Created: 2021-06-22 12:43:05 UTC Authoring application: Microsoft Excel 16.0300
MD5: 45bc3dcb0be2fe29c99f51ac3a7230c6 SHA-1: 7f3dea461346ecd674d5ceafc5d3be83ed12c14c SHA-256: c3e12a45ab7b36806729ac50cdd4e782599616d80f5ed9095f1156c7e3e9d679
160 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.003 Windows Command Shell T1566.001 Spearphishing Attachment

The OOXML document contains VBA macros that reference PowerShell and cmd.exe. The GetObject call suggests an attempt to load and execute external code. The VBA code includes a Base64 decoding function, indicating that malicious code is likely obfuscated within the macro and then executed. This points to a macro-based downloader pattern.

Heuristics 4

  • PowerShell reference in VBA critical OLE_VBA_PS
    PowerShell reference in VBA
  • GetObject call high OLE_VBA_GETOBJ
    GetObject call
  • cmd.exe reference in VBA high OLE_VBA_CMD
    cmd.exe reference in VBA
  • VBA project inside OOXML medium OOXML_VBA
    Document contains a VBA project — VBA macros present

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
6f1e2c7538896082b4d3cc925d33226c081e8b3b29faa9818d64633a6762f047
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 34430 bytes
vbaProject_00.bin
26197bbe732270e7de25badffd33bdeb6151e440d4e7799facdadb666c6fcc61
vba-project OOXML VBA project: xl/vbaProject.bin 11264 bytes