Last Updated: 2016-12-10 20:23:20 UTC
by Didier Stevens (Version: 1)
Diary reader Wayne Smith shared an interesting malicious document with us. Wayne also provided us with his own analysis: this malicious document sleeps and checks the time online before it activates its payload.
It's a .docx file that contains 4 embedded objects. When we calculate the hashes, we see that the 4 documents are identical:
As all objects are identical, we just need to analyze one object:
It's a VBS file, let's extract it:
Analysis of this obfuscated code reveals that it is a downloader with a particular property (for a maldoc): before downloading and executing the payload, this VBS code will sleep for 5 minutes, checking the elapsed time every minute by querying http://time.nist.gov:13.
By sleeping and checking the time online, this sample hopes to evade detection by sandboxes that do time acceleration without interfering with online time checking. This sample will sleep indefinitely when online time querying fails.