Skip to main content

Command Palette

Search for a command to run...

Emulation FTW!

Updated
•9 min read•View as Markdown
D
Passionate about the defensive side of cyber security. I just want to hunt for and disrupt threat actor activity and protect others

Sample from Samplepedia

Goal: Extract the next stage download url

# File Information

  • File Type: Microsoft Encrypted Structured Storage Object || CDFV2 Encrypted CDFV2 Encrypted indicates that a Microsoft Office document (such as .doc, .docx, .xls, or .xlsx) is password-protected and stored in the Compound Document Format v2

  • SHA256 Hash: 13063a496da7e490f35ebb4f24a138db4551d48a1d82c0c876906a03b8e83e05

  • MD5 Hash: 02efd596d71089ed8db9062b5adb762f

  • Virus Total Verdict: Malicious

# Executive Summary

The analyzed file is a malicious, password-protected Office document that uses embedded shellcode to download a second-stage payload (vbc.exe) from 104.168.32[.]50 into the Public folder. It was obfuscated with the default password VelvetSweatShop, which was easily bypassed to reveal the malicious payload.

Analysis

I started by getting some metadata and more file information about the file. This also confirmed that the file is indeed encrypted with a password.

Metadata / File Info

olemeta

--------------------+--------------------+----------+--------------------------
Indicator           |Value               |Risk      |Description               
--------------------+--------------------+----------+--------------------------
File format         |Generic OLE file /  |info      |Unrecognized OLE file.    
                    |Compound File       |          |Root CLSID:  - None       
                    |(unknown format)    |          |                          
--------------------+--------------------+----------+--------------------------
Container format    |OLE                 |info      |Container type            
--------------------+--------------------+----------+--------------------------
Encrypted           |True                |low       |The file is encrypted. It 
                    |                    |          |may be decrypted with     
                    |                    |          |msoffcrypto-tool          
--------------------+--------------------+----------+--------------------------
VBA Macros          |No                  |none      |This file does not contain
                    |                    |          |VBA macros.               
--------------------+--------------------+----------+--------------------------
XLM Macros          |No                  |none      |This file does not contain
                    |                    |          |Excel 4/XLM macros.       
--------------------+--------------------+----------+--------------------------
External            |0                   |none      |External relationships    
Relationships       |                    |          |such as remote templates, 
                    |                    |          |remote OLE objects, etc   
--------------------+--------------------+----------+--------------------------

oledir

----+------+-------+----------------------+-----+-----+-----+--------+------
id  |Status|Type   |Name                  |Left |Right|Child|1st Sect|Size  
----+------+-------+----------------------+-----+-----+-----+--------+------
0   |<Used>|Root   |Root Entry            |-    |-    |1    |3       |832   
1   |<Used>|Stream |EncryptionInfo        |3    |2    |-    |0       |224   
2   |<Used>|Stream |EncryptedPackage      |-    |-    |-    |C       |264776
3   |<Used>|Storage|\x06DataSpaces        |-    |-    |5    |0       |0     
4   |<Used>|Stream |Version               |-    |-    |-    |4       |76    
5   |<Used>|Stream |DataSpaceMap          |4    |6    |-    |6       |112   
6   |<Used>|Storage|DataSpaceInfo         |-    |8    |7    |0       |0     
7   |<Used>|Stream |StrongEncryptionDataSp|-    |-    |-    |8       |64    
    |      |       |ace                   |     |     |     |        |      
8   |<Used>|Storage|TransformInfo         |-    |-    |9    |0       |0     
9   |<Used>|Storage|StrongEncryptionTransf|-    |-    |10   |0       |0     
    |      |       |orm                   |     |     |     |        |      
10  |<Used>|Stream |\x06Primary           |-    |-    |-    |9       |208   
11  |unused|Empty  |                      |-    |-    |-    |0       |0     
----+----------------------------+------+--------------------------------------
id  |Name                        |Size  |CLSID                                 
----+----------------------------+------+--------------------------------------
0   |Root Entry                  |-     |                                      
3   |\x06DataSpaces              |-     |                                      
6   |  DataSpaceInfo             |-     |                                      
7   |StrongEncryptionDataSpace   |64    |                                      
5   |  DataSpaceMap              |112   |                                      
8   |  TransformInfo             |-     |                                      
9   |StrongEncryptionTransform   |-     |                                      
10  |      \x06Primary           |208   |                                      
4   |  Version                   |76    |                                      
2   |EncryptedPackage            |264776|                                      
1   |EncryptionInfo              |224   |                                

oledump

  1:        64 '\x06DataSpaces/DataSpaceInfo/StrongEncryptionDataSpace'
  2:       112 '\x06DataSpaces/DataSpaceMap'
  3:       208 '\x06DataSpaces/TransformInfo/StrongEncryptionTransform/\x06Primary'
  4:        76 '\x06DataSpaces/Version'
  5:    264776 'EncryptedPackage'
  6:       224 'EncryptionInfo'

This indicates that there are encrypted streams within this file. Stream 5 is the stream that contains the encrypted blob.

Decryption

I used the officecrypt unit from binary refinery to decrypt the file. The file is just encrypted with the default password for encrypting Microsoft Office documents:

VelvetSweatShop.

Before Decryption

Using peek from binary refinery, it shows that the file is encrypted:

This was my command: ef <filename> | peek

After Decryption

In contrast, taking a "peek" at the file after using officecrypt, shows the actual magic bytes and strings typical of a MS Office document.

This was my command: ef <filename> | officecrypt | peek

I also used msoffcrypto-tool to confirm this. This was my command:

msoffcrypto-tool <inputfile> <outputfile> -p <password>

Both files have the same hash, so the decryption worked.

I used oledump to see the various streams in the file. Because it is not the legacy OLE format, some of the oletools can't work with it.

oledump

This was the output of oledump:

A: xl/embeddings/oleObject1.bin
 A1:        20 '\x01Ole'
 A2:      1215 '\x01oLE10NATive'

It looks like there is an embedded ole object within the XLSX document. I opened it in malcat and dumped that ole object to disk.

There was a macro-enabled document and an oleObject embedded in the file.

These are the files:

Microsoft_Office_Word_Macro-Enabled_Document1.docm: Microsoft Word 2007+ || Word Microsoft Office Open XML Format document
oleObject1.bin: Composite Document File V2 Document, Cannot read section info || Generic OLE2 / Multistream Compound

I couldn't find any relevant info from the .docm file. I went ahead to analyze the oleObject file using oledump.

oledump

oledump <olefile>

  1:        20 '\x01Ole'
  2:      1215 '\x01oLE10NATive'

I made attempt to look at strings from stream 2 (x01oLE10NATive), but just saw gibberish.

PXPX
!W__
Q5/:
yN4[ 
w	uT2$g
liz`
YY)I
LnpL
A1>^
h	.2*
ca6h
gFYcQ
aAAM!
0M}p

My next step was to dump the contents of that stream to disk.

Command: oledump <olefile> -s 2 -d > <output.bin>

After looking at the hex of the file, it looks supiciously like shellcode. Here is a "peek":

---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
01.215 kB; 94.42% entropy; data
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
000000: 00 2F 1E 02 03 7E 01 EB 47 0A 01 05 75 63 A3 EC 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 06 45 00 00 00 00 00 00 00 00 00 00 00 00 00  ./...~..G...uc...........................P.E.............
000039: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 29 C3 44 00 00 00 00 57 5F EB 75 81 C7 84 01 00 00 8D AF 6D 02 00 00 EB 57 EB 28 EB EE EB 1C 69 C0 C7 3C 00 7C EB 05 B4 73  ................).D....W_.u........m....W.(....i..<.|...s
000072: 38 66 E1 05 11 50 CA 57 EB 12 EB 3B EB E4 50 58 50 58 EB 31 EB DC EB 46 EB 70 EB 48 EB 71 31 07 9C 53 57 53 81 C3 BC 5F 00 00 81 C3 B7 44 00 00 81 EB 85 2F 00 00 8D 9B 80  8f...P.W...;..PXPX.1...F.p.H.q1..SWS..._.....D...../.....
0000AB: 2A 00 00 5B 5F 5B 9D 83 C7 04 EB 10 EB 17 6B C0 00 EB 3E EB 04 04 21 57 5F 5F EB BF EB 07 E8 F6 FF FF FF EB F4 39 EF EB 2F EB A6 EB B8 EB 8E 9C 53 8D 9B 48 4F 00 00 81 EB  *..[_[........k...>...!W__...........9../.......S..HO....
0000E4: 49 1C 00 00 81 C3 35 69 00 00 90 81 EB 67 12 00 00 5B 9D E9 68 FF FF FF E9 67 FF FF FF EB 8D 0F 82 5F FF FF FF E9 44 01 00 00 4F 38 58 A5 4A 2E 16 0A BE 30 F6 CF 78 41 C7  I.....5i.....g...[..h....g......._....D...O8X.J....0..xA.
00011D: 18 9E B0 CE E4 E2 46 08 60 D6 97 5F 14 14 3B F3 35 91 0A 5D D3 D4 64 E5 28 39 6B C7 D0 30 45 75 0C 7A 5A D4 FF 6E 9C 7D F2 3A BC FE 92 1D 6F 19 2E A7 B0 00 FB 02 FD A0 4F  ......F.`.._..;.5..]..d.(9k..0Eu.zZ..n.}.:....o.........O
000156: 29 98 D5 EA 2B C8 AF 2A 6B 17 B6 54 DF 95 20 CF 56 10 1C 69 AB 62 0B 91 13 A5 C1 9A 55 74 C9 00 0E 35 A1 9D EB 4D F8 F1 F1 66 F4 61 B6 AE 6F 74 A5 16 36 17 3D 97 4A DB 54  )...+..*k..T....V..i.b......Ut...5...M...f.a..ot..6.=.J.T
00018F: 6B 1E 35 4F 4D DF BB 69 C4 A9 68 F1 53 CE E1 8C C4 10 A6 71 67 EC 63 AA 4E CD 21 56 8E 54 90 EA 81 9A 48 6B 08 62 FD B7 C3 70 CD BC 5A B0 79 BD B3 8A A6 90 41 16 19 E2 36  k.5OM..i..h.S......qg.c.N.!V.T....Hk.b...p..Z.y.....A...6
0001C8: 60 02 74 C4 AE 2D 54 6B B0 52 2E 23 D2 48 7C B3 71 4C CC E1 1E 3B 01 B4 DF DD 95 BD 6C 19 D2 4F 71 3B 16 BD D4 34 14 A3 E5 D7 15 20 AF 1E 35 15 32 63 A1 6A 9B A6 DC 46 92  `.t..-Tk.R.#.H|.qL...;......l..Oq;...4........5.2c.j...F.
000201: CF FF 5B 70 E3 F5 19 80 4E BD F6 46 23 AA AE B6 54 A2 7D 7A FA 63 67 2D 92 BA 72 A5 3B CC EA 21 F9 4E 98 9F F5 CD 14 0B BB E8 F1 85 7C 93 09 A4 4B 53 BC B1 61 86 2B E7 5B  ..[p....N..F#...T.}z.cg-..r.;..!.N..........|...KS..a.+.[
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

I decided to use scdbg to confirm this. Using the Findsc option, I can see where shellcode is within the binary.

I decompiled the binary using rizin and the code at 0x50 looks like the most interesting portion of the code, so I selected that offset to emulate.

       └──> 0x00000050      push  rdi
            ; CALL XREF from fcn.000000c4 @ +0x353
            0x00000051      pop   rdi
        ┌─< 0x00000052      jmp   0xc9
│       │   ; CODE XREF from fcn.000000c4 @ 0x64
│       │   ; DATA XREF from fcn.000000c4 @ +0x9c
│      ┌──> 0x00000054      add   edi, 0x184
│      ╎│   0x0000005a      lea   ebp, qword [rdi+0x26d]
│     ┌───< 0x00000060      jmp   0xb9
     ┌────< 0x00000062      jmp   0x8c
│    ││││   ; CODE XREFS from fcn.000000c4 @ 0x7e, 0x86
│    ││││   ; CODE XREF from fcn.000000c4 @ +0x33
│   ┌──└──< 0x00000064      jmp   0x54
    ╎││┌──< 0x00000066      jmp   0x84
│   ╎││││   ; CODE XREFS from fcn.000000c4 @ 0x14, 0xfc
│   ╎││││   0x00000068      imul  eax, eax, 0x7c003cc7
│  ┌──────< 0x0000006e      jmp   0x75
   │╎││││   ; CALL XREF from fcn.000000c4 @ +0x13e
   │╎││││   0x00000070      mov   ah, 0x73                             ; 's'
   │╎││││   ; DATA XREF from fcn.000000c4 @ +0x1fd
   │╎││││   0x00000072      cmp   byte [rsi-0x1f], ah
│  │╎││││   ; CODE XREF from fcn.000000c4 @ 0x6e
│  └──────> 0x00000075      add   eax, 0x57ca5011
│  ┌──────< 0x0000007a      jmp   0x8e
   │╎││││   ; CODE XREF from fcn.000000c4 @ +0x10
  ┌───────< 0x0000007c      jmp   0xb9                                 ; fcn.000000c4-0xb
  ││└─────< 0x0000007e      jmp   0x64                                 ; fcn.000000c4-0x60
  ││ ││││   0x00000080      push  rax

Emulation ftw!!!!!

In reverse engineering, emulation means running a program inside a simulated environment instead of directly on the real operating system. It allows analysts to observe its behavior safely and in detail. Tools such as scdbg and Speakeasy emulate enough of the CPU and Windows environment for malware or shellcode to execute, while modeling Windows APIs such as VirtualAlloc, LoadLibrary, or CreateProcess. As the code runs, the emulator can record instructions, API calls, arguments, memory activity, and other behavior, helping analysts understand what the program is doing without necessarily executing its actions on a real system.

I was able to see that the program uses the URLDownloadToFileW Windows API function to download a file, vbc.exe, from hxxp[://]104.168.32[.]50//009/ and saves it C:\Users\Public\vbc.exe.