MALICIOUS
420
Risk Score
Heuristics 7
-
CVE-2008-2244 — Microsoft Word record-parsing payload critical CVE likely CVE_2008_2244Word OLE document has normal small WordDocument/table streams, a large unallocated OLE slack region, and an executable or resolver shellcode payload in that slack. This is the static shape of the MS08-042 Word record-parsing exploit family tracked as CVE-2008-2244.
-
PowerPoint binary-format RCE payload — CVE-2011-1269 / MS11-036 family critical CVE likely PPT_BINARY_MEMORY_CORRUPTION_PAYLOADA macro-free binary PowerPoint (.ppt) document carries a native code payload (embedded PE and/or process-injection shellcode), staged in an oversized binary stream. Legitimate presentations do not embed executables or shellcode; this is the payload half of a PowerPoint memory-corruption exploit (CVE-2011-1269 / MS11-036 family; the same record-overflow delivery is shared with CVE-2010-2572 and CVE-2009-0556).
-
Office EPRINT stream contains EMF object high OLE_EPRINT_EMF_OBJECTOLE ObjectPool contains an EPRINT stream with EMF data. This is rare in normal documents and is related Office object-delivery evidence when paired with exploit payload anomalies, but the malformed graphics record required for exact CVE attribution is not proven by this rule alone.
-
ClamAV: Win.Trojan.Poison-4232 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Trojan.Poison-4232
-
Embedded PE executable critical OLE_EMBEDDED_EXEMZ/PE header found inside document — possible embedded executable
-
PEB access via FS segment (x86) high SC_PEB_ACCESSPEB access via FS segment (x86)Disassembly hidden — these bytes score as degenerate, not coherent x86 code (single mnemonic 'mov' is 56% of instructions — a sled or padding/filler run, not program logic).
-
OLE document has large unaccounted-for region high OLE_SLACK_ANOMALYOLE file is 236,032 bytes but its declared streams total only 40,506 bytes — 195,526 bytes (83%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_office_0000bc00.exe |
embedded-pe | Office MZ+PE at offset 0xBC00 | 187904 bytes |
SHA-256: 70eea7dd1a705bb1b98e7069578dfeea398629bea172a554a9babafa7a8e92e2 |
|||
|
Detection
ClamAV:
Win.Trojan.Poison-4232
Obfuscation or payload:
unlikely
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.