Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 022c209e582010c3…

MALICIOUS

Office (OLE)

48.0 KB Created: 2018-01-23 18:58:00 Authoring application: Microsoft Office Word First seen: 2018-02-19
MD5: f156a81952a8c221ffcd8ab027912e0c SHA-1: 71d64775d16545175e2718b7cce9012d3cc111ad SHA-256: 022c209e582010c39023e3f4850bb2952103ee3d35bc25fe459e8e2055364d9f
142 Risk Score

Malware Insights

MITRE ATT&CK
T1218.005 Client Execution: Signed Binary Proxy Execution T1566.001 Spearphishing Attachment

The sample leverages Dynamic Data Exchange (DDE) to execute certutil.exe, which is instructed to download a file from 'http://currency.alderaantours.com/cows.xml'. The downloaded file is saved locally and then potentially processed by MSBuild.exe. This indicates a dropper functionality designed to fetch and execute a secondary payload.

Heuristics 4

  • ClamAV: Doc.Dropper.Agent-6451049-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6451049-0
  • Reference to certutil (download/decode) high SC_STR_CERTUTIL
    Reference to certutil (download/decode)
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://currency.alderaantours.com/cows.xml In document text (OLE body)
    • http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)