Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 f16322edfe747852…

MALICIOUS

Office (OOXML) / .DOC

2.83 MB Created: 2022-08-18 13:26:00 UTC Authoring application: Microsoft Office Word 14.0000 First seen: 2022-08-18
MD5: b4a9a31706339da9a444be681790fe4f SHA-1: a12d5cc82fdcaab2cc0e9a6c9a616913f45ea9a0 SHA-256: f16322edfe74785294472eeb36623e6407fdfdd5590ec5800eeb7c3a9bf27125
182 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File T1071.001 Web Protocols

The sample contains a VBA macro that is triggered by the Document_Open event. This macro appears to be designed to download and execute a second-stage payload, as indicated by the use of GetObject and CallByName functions, and the obfuscated string references. The macro's obfuscation and the presence of a renamed VBA project part suggest an attempt to evade detection.

Heuristics 6

  • VBA project part renamed to evade filename detection high OOXML_VBA_PROJECT_RENAMED
    The VBA project is bound through the OOXML relationship/content type but its part is not named vbaProject.bin. Legitimate Office producers always emit vbaProject.bin; renaming it hides the macros from path-only scanners (observed in the SVCReady loader).
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • GetObject call high OLE_VBA_GETOBJ
    GetObject call
  • CallByName call high OLE_VBA_CALLBYNAME
    CallByName call
  • VBA project inside OOXML medium OOXML_VBA
    Document contains a VBA project — VBA macros present (project part renamed away from vbaProject.bin: word/mWEGIjmxWh.bin)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
578ff80b90170be14e91e54065b8d99280bda269d1873f3c549104a2f6d62927
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 11883 bytes
vbaProject_00.bin
d49cb21c0927772bed4eca4c57d90b3bfec0cad8b535888256553f7556214574
vba-project OOXML VBA project: word/mWEGIjmxWh.bin 13312 bytes