Emotet — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c57c795a24c11be4…

MALICIOUS

Office (OOXML) / .XLSX

4.88 MB Created: 2021-05-17 14:31:34 UTC Authoring application: Microsoft Excel 15.0300
MD5: ea6cfa4d13d5d658119e205b67a7fb88 SHA-1: 5d64297a2e0b3f07b177b2cb887228294c271313 SHA-256: c57c795a24c11be4c317d96e39da5aa4552f6cabe4e1259cff034d11da11dba7
290 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1059.003 Windows Command Shell

The presence of a Workbook_Open macro and the use of Shell() and CreateObject() calls strongly indicate malicious intent. ClamAV detections for 'Doc.Downloader.Emotet' further support this. The script likely downloads and executes a second-stage payload from one of the embedded URLs.

Heuristics 8

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • ClamAV: Doc.Downloader.Emotet-10019767-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Emotet-10019767-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL https://akselhortum.com/UserFiles/urunler/sel-hortumlari/bezli-su-hortumlari/T7Rlgivlnw7.phptq
    • https://on-theweb.com/highlinetrail/2wUjN8d0D.phpP+Gcow6z;/P
    • https://atozcomputers.ie/blog/wp-content/uploads/2016/08/2kSSfoVcaBE.php|wldgiq5w
    • https://congxepsaigon.net/wp-content/themes/twentynineteen/sass/blocks/cMRovqbpE.php
    • https://hotel.aims.org.ng/yX5roDTNU.php$!B3-

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
e2354774d74ed0377cc7c5dd99f595671099e46da34e504ca524a4bd8a703e55
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 3975326 bytes
vbaProject_00.bin
cc19b02895c67d26e76f534a500041637b157f95e37da434a7abb8f2401d9742
vba-project OOXML VBA project: xl/vbaProject.bin 7584256 bytes
Detection
ClamAV: Doc.Downloader.Emotet-10019767-0
Obfuscation or payload: unlikely