Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 f98a6453ce1ac501…

MALICIOUS

Office (OLE) / .XLS

685.0 KB Created: 2019-08-30 09:14:50 Authoring application: Microsoft Excel
MD5: 92eb045c1b489ec120bf358975522403 SHA-1: 03665eef72e43b0bb8e2679cd7f544b26698a394 SHA-256: f98a6453ce1ac5016adc2666c54f47a46f66f2ee21c565439a2cd34a8de85364
400 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1105 Ingress Tool Transfer T1059.003 Windows Command Shell

The sample is an Excel file containing VBA macros and an embedded PE executable. Heuristics indicate the use of Shell(), VirtualAlloc, LoadLibrary, and GetProcAddress, suggesting the macro is designed to load and execute the embedded payload. The embedded executable is detected by ClamAV as Win.Dropper.Hideproc-6663113-0. The presence of an unknown reputation URL is noted as a potential indicator.

Heuristics 10

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • ClamAV: Win.Dropper.Hideproc-6663113-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Dropper.Hideproc-6663113-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.microsoft.com0
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0Z
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
346fc2c637da2638dc9f1bfb1d0cf62937da1de49da2d171d086babe9247095f
vba-macro oletools.olevba.extract_macros (decoded VBA source) 14393 bytes
embedded_office_000042f1.exe
7b88d6879e5098fe4c3bd33ae8a8c9bac746efdcc383ec04f1789c2fba32ce06
embedded-pe Office MZ+PE at offset 0x42F1 684303 bytes
Detection
ClamAV: Win.Dropper.Hideproc-6663113-0
Obfuscation or payload: unlikely
ole10native_00.bin
ac59e09e5f57cbbfbb805c91441f27be5d95148d2de3360ad879c53100cd7b23
ole-package OLE Ole10Native stream: MBD0017F447/Ole10Native 562717 bytes