Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 ef6a2bf769a956ab…

MALICIOUS

Office (OOXML) / .DOC

377.9 KB Created: 2023-02-17 19:56:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-02-18
MD5: 8ac4ed115562301f814f5ab1b46fa42a SHA-1: e88e4bc5ba81d56bb4c756eb93aa23b83e8f39be SHA-256: ef6a2bf769a956ab5f942451867691cc68e440dc8bca9c55525f710d736c1f00
162 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.005 Visual Basic

The sample utilizes an embedded OLE object that leverages CVE-2017-0199 to fetch and execute a secondary payload from the URL https://urlpropogationintimitacy.blogspot.com/atom.xml. Additionally, an embedded VBA macro project was identified, pointing to a payload hosted on mediafire at https://www.mediafire.com/file/vyr45w2x2mq3gnq/1pat6000.txt/file. These elements strongly indicate a downloader or dropper functionality.

Heuristics 5

  • OOXML OLE2Link remote loader — CVE-2017-0199 related high CVE related CVE_2017_0199_RELATED
    Document contains an o:OLEObject Type=Link whose external oleObject relationship points to a remote URL. This is the OOXML OLE2Link activation shape associated with CVE-2017-0199 delivery, but the local file does not expose URL Moniker bytes or a weaponized extension/content type, so the exact CVE cannot be proven statically.
  • Embedded Office object carries macros critical OFFICE_EMBEDDED_MACRO_OBJECT
    This document embeds a second Office file that itself contains a VBA macro project or an Excel 4.0 (XLM) macro sheet. Hiding a macro-bearing workbook or document inside another document — frequently under an obfuscated, non-standard part name — is a macro-smuggling technique that defeats scanners which only inspect the outer document's macro storage. No benign authoring workflow stages a hidden macro project this way.
  • External OLE object relationship high OOXML_EXTERNAL_OLE_OBJECT
    Document contains an oleObject relationship whose target is an external HTTP(S) URL. Office resolves this through OLE/object update paths rather than as a normal user-clicked hyperlink.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.mediafire.com/file/m7oygqrz43p13io/TempHOtel.docx
    • https://www.mediafire.com/file/vyr45w2x2mq3gnq/1pat6000.txt/file
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml
    • https://urlpropogationintimitacy.blogspot.com/atom.xml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
1617438a6ef2dd3687b2ea8f39b61f37aedbc7b73b4ad96152d3b0b42d14135c
ooxml-ole-object OOXML embedded OLE part: word/embeddings/_____._____ 15735 bytes