Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 2ae0ab67f18b2a1e…

MALICIOUS

Office (OLE)

49.5 KB Created: 2017-11-13 21:27:00 Authoring application: Microsoft Office Word First seen: 2022-07-25
MD5: 258801e9816c4214a4c337f9adb198d3 SHA-1: 7c0eaf559ab71214042801006bfe8a8cebd5d5d2 SHA-256: 2ae0ab67f18b2a1e995423694f9cf29c75b5102378ba8f85d37b4498d97faaea
282 Risk Score

Heuristics 6

  • CVE-2007-3899 — Microsoft Word malformed string memory corruption critical CVE likely CVE_2007_3899
    Word OLE document has the MS07-060 malformed-string exploit shape: a Word 97-family FIB points to a malformed DOP/string-table region with an abnormal INT_MAX run, inflated text counters, and exploit payload or Mdropper.Z campaign evidence.
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Ole10Native package payload is a download-and-execute script critical OFFICE_PACKAGE_SCRIPT_DROPPER
    The OLE Package's embedded payload contains a script that hosts a shell (PowerShell/WScript/mshta), fetches a remote resource, and executes it — a download-and-run dropper. Embedding such a script inside an Office document via the Object Packager is a direct user-execution delivery technique (MITRE T1204.002), not a benign attachment.
  • Ole10Native package drops an auto-executable payload critical OFFICE_PACKAGE_RISKY_FILE
    OLE Package displayName or fullPath ends in a directly auto-executable extension (a runnable binary or a script the default shell host runs on double-click). Embedding such a payload inside an Office document has no benign authoring use — it is a malware-delivery dropper.
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/SMI/2005/WindowsSettings Embedded OLE package script
    • http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_00002c67.exe embedded-pe Office MZ+PE at offset 0x2C67 39321 bytes
SHA-256: f3d4e44793eb6911f77a128c7aa7608bc65ab9dc7daca7fe5ba50d71bfe35df3
ole10native_00.bin ole-package OLE Ole10Native stream: ObjectPool/_1572084892/Ole10Native 31511 bytes
SHA-256: 27b1184d4767c5478f846eacf62dc6d3f68e41ed0a09e6cdbd7b896e288b73d9
ole10native_00_calc.exe ole-package-payload OLE Ole10Native payload: ObjectPool/_1572084892/Ole10Native; display_name=calc.exe; full_path=C:\Users\xxxxx\AppData\Local\Temp\calc (2).exe; temp_path=; def_file= 31232 bytes
SHA-256: c74f41325775de4777000161a057342cc57a04e8b7be17b06576412eff574dc5