Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 facbb3cc801298e2…

MALICIOUS

Office (OOXML) / .DOC

66.1 KB Created: 2021-05-25 09:14:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: f581badfafe9b2e54cf9736f573f060a SHA-1: 5468f63a06de91ce05c5c2227a2a24f258144009 SHA-256: facbb3cc801298e2aa5d66f11e758ca7c57a3d4d4c5692ff9bb75d36e393e95b
102 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is a malicious OOXML document containing VBA macros, indicated by the OOXML_VBA and OLE_VBA_DOCOPEN heuristics. The presence of a Document_Open macro and a GetObject call suggests that the macro executes automatically when the document is opened. No specific IOCs like URLs or hashes were extracted, but the macro's execution is the primary threat.

Heuristics 4

  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • GetObject call high OLE_VBA_GETOBJ
    GetObject call
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/photoshop/1.0/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
eabaea3eb8b0c52513e3ed3c6fd374499d7b5bbf02a5772aa70bab5e77939ac9
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 985 bytes
vbaProject_00.bin
2e9bb8fc00e65d25a0924cc48234dd88bc5c246ce2af21029f609320306b0fee
vba-project OOXML VBA project: word/vbaProject.bin 17408 bytes