Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 0271e462c85ac68f…

MALICIOUS

Office (OLE) / .DOC

973.0 KB Created: 2021-05-19 11:37:00 Authoring application: Microsoft Office Word
MD5: 4d0bfbb8b9d68d1304ab5551672e3eb7 SHA-1: 4a5461e3d50002965559511bcb29c0e98245adda SHA-256: 0271e462c85ac68f34406bc9ad70fa3fbf8bdf0c8b94f3219c07c76d543611ad
502 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File T1105 Ingress Tool Transfer T1566.001 Spearphishing Attachment

The sample is a malicious Office document containing a VBA macro that executes upon opening. The macro attempts to find and execute an embedded PE executable named 'fax.f' (which is renamed to 'zs.z' in the startup directory) using 'rundll32.exe'. This indicates a clear intent to download and execute a second-stage payload, likely for further system compromise.

Heuristics 14

  • Office EPRINT stream contains EMF object high CVE related OLE_EPRINT_EMF_OBJECT
    OLE ObjectPool contains an EPRINT stream with EMF data. This is rare in normal documents and is CVE-2007-3893/MS07-046-family evidence when paired with Office exploit payload anomalies, but the malformed EMF record is not proven by this rule alone.
  • OLE with Ole10Native — possible CVE-2026-21514 exploitation high CVE likely CVE_2026_21514
    Document contains a Word OLE object with Ole10Native plus executable, PE, or risky remote-link indicators. CVE-2026-21514 exploits OLE metadata validation; this stronger structure is treated as likely exploitation.
  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • Reference to VirtualProtect API medium SC_STR_VIRTUALPROTECT
    Reference to VirtualProtect API
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
a90963d5d6c74d486b2956916b800b6ec29cbd6400e3d375efd2c0f312d5e9fa
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1426 bytes
embedded_office_0008ec68.exe
56cd0bc65cfcc9b4bdb44594a7764039bf22c968e044c8aae031b35fbaa84dd1
embedded-pe Office MZ+PE at offset 0x8EC68 411544 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
ole10native_00.bin
0b889b5de6de15e22c944e86f6e5f734b0c1ea194bcc222633ec6c689d65ddf0
ole-package OLE Ole10Native stream: ObjectPool/_1682904495/Ole10Native 385306 bytes