Malicious Office (OLE) / .DO — malware analysis report

Static analysis result for SHA-256 1461ab47cd953190…

MALICIOUS

Office (OLE) / .DO

146.0 KB
MD5: dc6249d6fb9d2f60c891caffa172a3e8 SHA-1: 6db6f39841a1e33025ebdfc112e9cdc5890b3e48 SHA-256: 1461ab47cd953190f07313e5d85882fdf9d7c5788dc490df9a6817b5df115a5f
300 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.003 Windows Command Shell

The sample exhibits high-confidence heuristics indicating the use of Windows API functions commonly associated with executing code, such as WinExec, CreateProcess, and LoadLibrary. The suspicious invocation of cmd.exe further suggests the execution of a malicious command or script. The OLE slack anomaly and EMF object within the EPRINT stream are structural indicators of potential obfuscation or embedded malicious content. The document body contains Chinese text related to file construction and embedded objects, but does not provide direct instructions.

Heuristics 8

  • Office EPRINT stream contains EMF object high CVE related OLE_EPRINT_EMF_OBJECT
    OLE ObjectPool contains an EPRINT stream with EMF data. This is rare in normal documents and is CVE-2007-3893/MS07-046-family evidence when paired with Office exploit payload anomalies, but the malformed EMF record is not proven by this rule alone.
  • Reference to WinExec API high SC_STR_WINEXEC
    Reference to WinExec API
  • Reference to CreateProcess API high SC_STR_CREATEPROCESS
    Reference to CreateProcess API
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 149,504 bytes but its declared streams total only 31,351 bytes — 118,153 bytes (79%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API