MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89ccaf26e055497d1bdc14fb644a07402a69beb33c38a151e2f4561d0ad766ef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Maldoc score: 7


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 89ccaf26e055497d1bdc14fb644a07402a69beb33c38a151e2f4561d0ad766ef
SHA3-384 hash: e8409c1c7aba206d35f25015d5b7f664098fff00189a307aef0a35dd2b45184acd9fd14924869875548948ed6d205157
SHA1 hash: d8199db1d53f38decc834b83dcab69cae7c33ac5
MD5 hash: 5885f7ebbc13a84356122f2f78a9b789
humanhash: fourteen-failed-robert-arkansas
File name:SecuriteInfo.com.Heur.318.23183
Download: download sample
File size:162'816 bytes
First seen:2022-04-15 16:42:18 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.ms-excel
ssdeep 3072:DynSGTyFRchUXmdand4NhZFGzElMPIrC5Ra5lQrrPTjjTB0p/5OQ65p1/15WMmfK:OnSGTyFRchUXmdand4NhZF+ElMPIrCio
TLSH T10BF35102FFB3CE75C789463298E267B86735DC248A25132730C577A87BF1EC4B919698
TrID 50.0% (.XLS) Microsoft Excel sheet (32500/1/3)
37.6% (.XLS) Microsoft Excel sheet (alternate) (24500/1/2)
12.3% (.) Generic OLE2 / Multistream Compound (8000/1)
Reporter SecuriteInfoCom
Tags:xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 7
OLE dump

MalwareBazaar was able to identify 27 sections in this file using oledump:

Section IDSection sizeSection name
1115 bytesCompObj
2488 bytesDocumentSummaryInformation
3252 bytesSummaryInformation
4114775 bytesWorkbook
5644 bytes_VBA_PROJECT_CUR/PROJECT
6152 bytes_VBA_PROJECT_CUR/PROJECTwm
797 bytes_VBA_PROJECT_CUR/UserFormMotifs/CompObj
8297 bytes_VBA_PROJECT_CUR/UserFormMotifs/VBFrame
91343 bytes_VBA_PROJECT_CUR/UserFormMotifs/f
102528 bytes_VBA_PROJECT_CUR/UserFormMotifs/o
118924 bytes_VBA_PROJECT_CUR/VBA/Feuil1
121150 bytes_VBA_PROJECT_CUR/VBA/Feuil2
132911 bytes_VBA_PROJECT_CUR/VBA/Module1
142334 bytes_VBA_PROJECT_CUR/VBA/ThisWorkbook
154209 bytes_VBA_PROJECT_CUR/VBA/UserFormMotifs
165079 bytes_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
172656 bytes_VBA_PROJECT_CUR/VBA/__SRP_0
18238 bytes_VBA_PROJECT_CUR/VBA/__SRP_1
19704 bytes_VBA_PROJECT_CUR/VBA/__SRP_2
20103 bytes_VBA_PROJECT_CUR/VBA/__SRP_3
21260 bytes_VBA_PROJECT_CUR/VBA/__SRP_4
2266 bytes_VBA_PROJECT_CUR/VBA/__SRP_5
231980 bytes_VBA_PROJECT_CUR/VBA/__SRP_6
24651 bytes_VBA_PROJECT_CUR/VBA/__SRP_7
25260 bytes_VBA_PROJECT_CUR/VBA/__SRP_8
26177 bytes_VBA_PROJECT_CUR/VBA/__SRP_9
27904 bytes_VBA_PROJECT_CUR/VBA/dir
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecWorkbook_OpenRuns when the Excel Workbook is opened
AutoExecchoixMotif1_ClickRuns when the file is opened and ActiveX objects trigger events
AutoExecWorksheet_ChangeRuns when the file is opened and ActiveX objects trigger events
SuspiciousHex StringsHex-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
450
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.Heur.318.23183
Verdict:
No threats detected
Analysis date:
2022-04-15 16:44:50 UTC
Tags:
macros macros-on-open

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
True
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
macros macros-on-open
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Result
Verdict:
UNKNOWN
Details
Macro with Startup Hook
Detected macro logic that will automatically execute on document open. Most malware contains some execution hook.
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  8/10
Tags:
macro macro_on_action
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Office loads VBA resources, possible macro or embedded object present
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments