Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 f00252ab17546cd9…

MALICIOUS

Office (OLE) / .XLS

409.0 KB Created: 2016-11-08 08:33:09 Authoring application: Microsoft Excel First seen: 2022-08-01
MD5: 9abd7cb96233b753f342f5e95110b10d SHA-1: ff9c4f0dbc0d7f1f910e8dfe78be3539a3b4f5b4 SHA-256: f00252ab17546cd922b9bda75942bebfed4f6cda4ae3e02dc390b40599ce1740
228 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1059 Command and Scripting Interpreter T1140 Deobfuscate or Obfuscate Malicious Code T1204.002 Malicious File

The sample contains VBA macros that utilize WScript.Shell and CreateObject to download and execute a second-stage payload. The script decodes a Base64 string from the document's 'Final Offer' sheet, writes it to disk as 'nvidiax.exe' in the temporary directory, and then executes it. The presence of WScript.Shell and Shell() calls strongly indicates an attempt to run arbitrary code.

Heuristics 6

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
54ba713ab254cfd6176a4b8846c3b0962e2e7a2f34b5c1107ba20bf283bf1595
vba-macro oletools.olevba.extract_macros (decoded VBA source) 7094 bytes