Win.Worm.Mantan-1 — Office (OOXML) malware analysis

Static analysis result for SHA-256 efbd07a8f2f9f4f3…

MALICIOUS

Office (OOXML)

14.8 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2021-08-20
MD5: ff60fc169a33321503597b61e8ba9217 SHA-1: 8a2b87084c32095fc36fee094ef02f2c56789262 SHA-256: efbd07a8f2f9f4f37c40de2212e7b7a39f4bc06771d4afbdaa339e12c888f9f7
102 Risk Score

Malware Insights

Win.Worm.Mantan-1 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is identified as Win.Worm.Mantan-1 by ClamAV. It contains a Visual Basic script that attempts to establish persistence by copying itself to system directories and adding entries to the Run registry keys. The script also attempts to lure the user into executing commands by instructing them to copy and paste content, likely to download and execute a second-stage payload from one of the embedded URLs.

Heuristics 3

  • ClamAV: Win.Worm.Mantan-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Worm.Mantan-1
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.skyinet.net/~young1s/HJKhjnwerhjkxcvytwertnMTFwetrdsfm In document text (OOXML body / shared strings)
    • http://www.skyinet.net/~angelcat/skladjflfdjghKJnwetryDGFikjUIyqwIn document text (OOXML body / shared strings)
    • http://www.skyinet.net/~koichi/jf6TRjkcbGRpGqaq198vbFV5hfFEkbopBdIn document text (OOXML body / shared strings)
    • http://www.skyinet.net/~chu/sdgfhjksdfjklNBmnfgkKLHjkqwtuHJBhAFSDIn document text (OOXML body / shared strings)
    • http://www.mirc.comIn document text (OOXML body / shared strings)