Malicious Office (OLE) / .PPT — malware analysis report

Static analysis result for SHA-256 ff8e48e52ca1647f…

MALICIOUS

Office (OLE) / .PPT

143.0 KB Created: 2021-02-23 23:59:34 Authoring application: Microsoft Office PowerPoint
MD5: a9a4bca034e3e1dffdabd05a67f956f3 SHA-1: a73c924ae959ed97a261c34a58e2d8c6609bca33 SHA-256: ff8e48e52ca1647f927116a72d0e9b9d719bb881cd9feeef42f7addfdb7e17bc
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell

The file is a PowerPoint presentation containing a VBA macro with an Auto_Open function. This macro utilizes the Shell() function, indicating an attempt to execute arbitrary commands. The presence of VBA p-code auto-execution with execution tokens further supports this. The specific command executed is not directly discernible from the provided heuristics, but the intent is to run an external process. No document body text was available for further context.

Heuristics 5

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
68f4ca7f7ff7ba99d6149c462758444a734cedde881e994fa7f85f65a3c36dbe
vba-macro oletools.olevba.extract_macros (decoded VBA source) 27504 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.