Emulation FTW!
Sample from Samplepedia
Goal: Extract the next stage download url
# File Information
File Type:
Microsoft Encrypted Structured Storage Object || CDFV2 EncryptedCDFV2 Encrypted indicates that a Microsoft Office document (such as .doc, .docx, .xls, or .xlsx) is password-protected and stored in the Compound Document Format v2SHA256 Hash:
13063a496da7e490f35ebb4f24a138db4551d48a1d82c0c876906a03b8e83e05MD5 Hash:
02efd596d71089ed8db9062b5adb762fVirus Total Verdict: Malicious

# Executive Summary
The analyzed file is a malicious, password-protected Office document that uses embedded shellcode to download a second-stage payload (vbc.exe) from 104.168.32[.]50 into the Public folder. It was obfuscated with the default password VelvetSweatShop, which was easily bypassed to reveal the malicious payload.
Analysis
I started by getting some metadata and more file information about the file. This also confirmed that the file is indeed encrypted with a password.
Metadata / File Info
olemeta
--------------------+--------------------+----------+--------------------------
Indicator |Value |Risk |Description
--------------------+--------------------+----------+--------------------------
File format |Generic OLE file / |info |Unrecognized OLE file.
|Compound File | |Root CLSID: - None
|(unknown format) | |
--------------------+--------------------+----------+--------------------------
Container format |OLE |info |Container type
--------------------+--------------------+----------+--------------------------
Encrypted |True |low |The file is encrypted. It
| | |may be decrypted with
| | |msoffcrypto-tool
--------------------+--------------------+----------+--------------------------
VBA Macros |No |none |This file does not contain
| | |VBA macros.
--------------------+--------------------+----------+--------------------------
XLM Macros |No |none |This file does not contain
| | |Excel 4/XLM macros.
--------------------+--------------------+----------+--------------------------
External |0 |none |External relationships
Relationships | | |such as remote templates,
| | |remote OLE objects, etc
--------------------+--------------------+----------+--------------------------
oledir
----+------+-------+----------------------+-----+-----+-----+--------+------
id |Status|Type |Name |Left |Right|Child|1st Sect|Size
----+------+-------+----------------------+-----+-----+-----+--------+------
0 |<Used>|Root |Root Entry |- |- |1 |3 |832
1 |<Used>|Stream |EncryptionInfo |3 |2 |- |0 |224
2 |<Used>|Stream |EncryptedPackage |- |- |- |C |264776
3 |<Used>|Storage|\x06DataSpaces |- |- |5 |0 |0
4 |<Used>|Stream |Version |- |- |- |4 |76
5 |<Used>|Stream |DataSpaceMap |4 |6 |- |6 |112
6 |<Used>|Storage|DataSpaceInfo |- |8 |7 |0 |0
7 |<Used>|Stream |StrongEncryptionDataSp|- |- |- |8 |64
| | |ace | | | | |
8 |<Used>|Storage|TransformInfo |- |- |9 |0 |0
9 |<Used>|Storage|StrongEncryptionTransf|- |- |10 |0 |0
| | |orm | | | | |
10 |<Used>|Stream |\x06Primary |- |- |- |9 |208
11 |unused|Empty | |- |- |- |0 |0
----+----------------------------+------+--------------------------------------
id |Name |Size |CLSID
----+----------------------------+------+--------------------------------------
0 |Root Entry |- |
3 |\x06DataSpaces |- |
6 | DataSpaceInfo |- |
7 |StrongEncryptionDataSpace |64 |
5 | DataSpaceMap |112 |
8 | TransformInfo |- |
9 |StrongEncryptionTransform |- |
10 | \x06Primary |208 |
4 | Version |76 |
2 |EncryptedPackage |264776|
1 |EncryptionInfo |224 |
oledump
1: 64 '\x06DataSpaces/DataSpaceInfo/StrongEncryptionDataSpace'
2: 112 '\x06DataSpaces/DataSpaceMap'
3: 208 '\x06DataSpaces/TransformInfo/StrongEncryptionTransform/\x06Primary'
4: 76 '\x06DataSpaces/Version'
5: 264776 'EncryptedPackage'
6: 224 'EncryptionInfo'
This indicates that there are encrypted streams within this file. Stream 5 is the stream that contains the encrypted blob.
Decryption
I used the officecrypt unit from binary refinery to decrypt the file. The file is just encrypted with the default password for encrypting Microsoft Office documents:
VelvetSweatShop.
Before Decryption
Using peek from binary refinery, it shows that the file is encrypted:
This was my command: ef <filename> | peek
After Decryption
In contrast, taking a "peek" at the file after using officecrypt, shows the actual magic bytes and strings typical of a MS Office document.
This was my command: ef <filename> | officecrypt | peek
I also used msoffcrypto-tool to confirm this. This was my command:
msoffcrypto-tool <inputfile> <outputfile> -p <password>
Both files have the same hash, so the decryption worked.
I used oledump to see the various streams in the file. Because it is not the legacy OLE format, some of the oletools can't work with it.
oledump
This was the output of oledump:
A: xl/embeddings/oleObject1.bin
A1: 20 '\x01Ole'
A2: 1215 '\x01oLE10NATive'
It looks like there is an embedded ole object within the XLSX document. I opened it in malcat and dumped that ole object to disk.
There was a macro-enabled document and an oleObject embedded in the file.
These are the files:
Microsoft_Office_Word_Macro-Enabled_Document1.docm: Microsoft Word 2007+ || Word Microsoft Office Open XML Format document
oleObject1.bin: Composite Document File V2 Document, Cannot read section info || Generic OLE2 / Multistream Compound
I couldn't find any relevant info from the .docm file. I went ahead to analyze the oleObject file using oledump.
oledump
oledump <olefile>
1: 20 '\x01Ole'
2: 1215 '\x01oLE10NATive'
I made attempt to look at strings from stream 2 (x01oLE10NATive), but just saw gibberish.
PXPX
!W__
Q5/:
yN4[
w uT2$g
liz`
YY)I
LnpL
A1>^
h .2*
ca6h
gFYcQ
aAAM!
0M}p
My next step was to dump the contents of that stream to disk.
Command: oledump <olefile> -s 2 -d > <output.bin>
After looking at the hex of the file, it looks supiciously like shellcode. Here is a "peek":
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
01.215 kB; 94.42% entropy; data
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
000000: 00 2F 1E 02 03 7E 01 EB 47 0A 01 05 75 63 A3 EC 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 06 45 00 00 00 00 00 00 00 00 00 00 00 00 00 ./...~..G...uc...........................P.E.............
000039: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 29 C3 44 00 00 00 00 57 5F EB 75 81 C7 84 01 00 00 8D AF 6D 02 00 00 EB 57 EB 28 EB EE EB 1C 69 C0 C7 3C 00 7C EB 05 B4 73 ................).D....W_.u........m....W.(....i..<.|...s
000072: 38 66 E1 05 11 50 CA 57 EB 12 EB 3B EB E4 50 58 50 58 EB 31 EB DC EB 46 EB 70 EB 48 EB 71 31 07 9C 53 57 53 81 C3 BC 5F 00 00 81 C3 B7 44 00 00 81 EB 85 2F 00 00 8D 9B 80 8f...P.W...;..PXPX.1...F.p.H.q1..SWS..._.....D...../.....
0000AB: 2A 00 00 5B 5F 5B 9D 83 C7 04 EB 10 EB 17 6B C0 00 EB 3E EB 04 04 21 57 5F 5F EB BF EB 07 E8 F6 FF FF FF EB F4 39 EF EB 2F EB A6 EB B8 EB 8E 9C 53 8D 9B 48 4F 00 00 81 EB *..[_[........k...>...!W__...........9../.......S..HO....
0000E4: 49 1C 00 00 81 C3 35 69 00 00 90 81 EB 67 12 00 00 5B 9D E9 68 FF FF FF E9 67 FF FF FF EB 8D 0F 82 5F FF FF FF E9 44 01 00 00 4F 38 58 A5 4A 2E 16 0A BE 30 F6 CF 78 41 C7 I.....5i.....g...[..h....g......._....D...O8X.J....0..xA.
00011D: 18 9E B0 CE E4 E2 46 08 60 D6 97 5F 14 14 3B F3 35 91 0A 5D D3 D4 64 E5 28 39 6B C7 D0 30 45 75 0C 7A 5A D4 FF 6E 9C 7D F2 3A BC FE 92 1D 6F 19 2E A7 B0 00 FB 02 FD A0 4F ......F.`.._..;.5..]..d.(9k..0Eu.zZ..n.}.:....o.........O
000156: 29 98 D5 EA 2B C8 AF 2A 6B 17 B6 54 DF 95 20 CF 56 10 1C 69 AB 62 0B 91 13 A5 C1 9A 55 74 C9 00 0E 35 A1 9D EB 4D F8 F1 F1 66 F4 61 B6 AE 6F 74 A5 16 36 17 3D 97 4A DB 54 )...+..*k..T....V..i.b......Ut...5...M...f.a..ot..6.=.J.T
00018F: 6B 1E 35 4F 4D DF BB 69 C4 A9 68 F1 53 CE E1 8C C4 10 A6 71 67 EC 63 AA 4E CD 21 56 8E 54 90 EA 81 9A 48 6B 08 62 FD B7 C3 70 CD BC 5A B0 79 BD B3 8A A6 90 41 16 19 E2 36 k.5OM..i..h.S......qg.c.N.!V.T....Hk.b...p..Z.y.....A...6
0001C8: 60 02 74 C4 AE 2D 54 6B B0 52 2E 23 D2 48 7C B3 71 4C CC E1 1E 3B 01 B4 DF DD 95 BD 6C 19 D2 4F 71 3B 16 BD D4 34 14 A3 E5 D7 15 20 AF 1E 35 15 32 63 A1 6A 9B A6 DC 46 92 `.t..-Tk.R.#.H|.qL...;......l..Oq;...4........5.2c.j...F.
000201: CF FF 5B 70 E3 F5 19 80 4E BD F6 46 23 AA AE B6 54 A2 7D 7A FA 63 67 2D 92 BA 72 A5 3B CC EA 21 F9 4E 98 9F F5 CD 14 0B BB E8 F1 85 7C 93 09 A4 4B 53 BC B1 61 86 2B E7 5B ..[p....N..F#...T.}z.cg-..r.;..!.N..........|...KS..a.+.[
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
I decided to use scdbg to confirm this. Using the Findsc option, I can see where shellcode is within the binary.
I decompiled the binary using rizin and the code at 0x50 looks like the most interesting portion of the code, so I selected that offset to emulate.
└──> 0x00000050 push rdi
; CALL XREF from fcn.000000c4 @ +0x353
0x00000051 pop rdi
┌─< 0x00000052 jmp 0xc9
│ │ ; CODE XREF from fcn.000000c4 @ 0x64
│ │ ; DATA XREF from fcn.000000c4 @ +0x9c
│ ┌──> 0x00000054 add edi, 0x184
│ ╎│ 0x0000005a lea ebp, qword [rdi+0x26d]
│ ┌───< 0x00000060 jmp 0xb9
┌────< 0x00000062 jmp 0x8c
│ ││││ ; CODE XREFS from fcn.000000c4 @ 0x7e, 0x86
│ ││││ ; CODE XREF from fcn.000000c4 @ +0x33
│ ┌──└──< 0x00000064 jmp 0x54
╎││┌──< 0x00000066 jmp 0x84
│ ╎││││ ; CODE XREFS from fcn.000000c4 @ 0x14, 0xfc
│ ╎││││ 0x00000068 imul eax, eax, 0x7c003cc7
│ ┌──────< 0x0000006e jmp 0x75
│╎││││ ; CALL XREF from fcn.000000c4 @ +0x13e
│╎││││ 0x00000070 mov ah, 0x73 ; 's'
│╎││││ ; DATA XREF from fcn.000000c4 @ +0x1fd
│╎││││ 0x00000072 cmp byte [rsi-0x1f], ah
│ │╎││││ ; CODE XREF from fcn.000000c4 @ 0x6e
│ └──────> 0x00000075 add eax, 0x57ca5011
│ ┌──────< 0x0000007a jmp 0x8e
│╎││││ ; CODE XREF from fcn.000000c4 @ +0x10
┌───────< 0x0000007c jmp 0xb9 ; fcn.000000c4-0xb
││└─────< 0x0000007e jmp 0x64 ; fcn.000000c4-0x60
││ ││││ 0x00000080 push rax
Emulation ftw!!!!!
In reverse engineering, emulation means running a program inside a simulated environment instead of directly on the real operating system. It allows analysts to observe its behavior safely and in detail. Tools such as scdbg and Speakeasy emulate enough of the CPU and Windows environment for malware or shellcode to execute, while modeling Windows APIs such as VirtualAlloc, LoadLibrary, or CreateProcess. As the code runs, the emulator can record instructions, API calls, arguments, memory activity, and other behavior, helping analysts understand what the program is doing without necessarily executing its actions on a real system.
I was able to see that the program uses the URLDownloadToFileW Windows API function to download a file, vbc.exe, from hxxp[://]104.168.32[.]50//009/ and saves it C:\Users\Public\vbc.exe.