Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 fd4e3fa8a8d9b59e…

MALICIOUS

Office (OOXML) / .DOC

50.5 KB Created: 2021-06-28 10:46:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: d1a988c49d988c0ce5eb76d5f0f16f2f SHA-1: 49b246f6b3e721f3466ddc3b018ed8c5fb671255 SHA-256: fd4e3fa8a8d9b59e58e08119e9aba18847b932c1ec8051b0544ebde855c19d46
262 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1059.003 Scheduled Task/Job T1566.001 Valid Accounts T1071.001 Application Layer Protocol – Web Protocols T1071.002 Web Service Infection T1071.003 Web Traffic T1105 System Information Discovery

The presence of a VBA macro within the OOXML document, combined with Shell() calls and cmd.exe references, strongly suggests a macro-based downloader. The Document_Open event triggers the malicious code, likely initiating the download and execution of a secondary payload. The extracted URLs, while benign in themselves, are likely used to facilitate this download. The ClamAV detection further confirms the malicious nature of the file. The obfuscated VBA code and the use of exceptionButtonException further indicate an attempt to evade detection.

Heuristics 7

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • ClamAV: Doc.Downloader.Ursnif06210-9875010-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Ursnif06210-9875010-0
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • cmd.exe reference in VBA high OLE_VBA_CMD
    cmd.exe reference in VBA
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
51aa4651fdd6979ef04aabe10e016ae9877f7b9d5fcc88d148daf1611346de9c
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1403 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
9db97e7c5590068048307f00f6a5fb362abd08eccd7c8c6ad1d3f05ffe776e49
vba-project OOXML VBA project: word/vbaProject.bin 17408 bytes