MALICIOUS
282
Risk Score
Heuristics 6
-
CVE-2007-3899 — Microsoft Word malformed string memory corruption critical CVE likely CVE_2007_3899Word OLE document has the MS07-060 malformed-string exploit shape: a Word 97-family FIB points to a malformed DOP/string-table region with an abnormal INT_MAX run, inflated text counters, and exploit payload or Mdropper.Z campaign evidence.
-
Embedded PE executable critical OLE_EMBEDDED_EXEMZ/PE header found inside document — possible embedded executable
-
Ole10Native package payload is a download-and-execute script critical OFFICE_PACKAGE_SCRIPT_DROPPERThe OLE Package's embedded payload contains a script that hosts a shell (PowerShell/WScript/mshta), fetches a remote resource, and executes it — a download-and-run dropper. Embedding such a script inside an Office document via the Object Packager is a direct user-execution delivery technique (MITRE T1204.002), not a benign attachment.
-
Ole10Native package drops an auto-executable payload critical OFFICE_PACKAGE_RISKY_FILEOLE Package displayName or fullPath ends in a directly auto-executable extension (a runnable binary or a script the default shell host runs on double-click). Embedding such a payload inside an Office document has no benign authoring use — it is a malware-delivery dropper.
-
Reference to ShellExecute API high SC_STR_SHELLEXECReference to ShellExecute API
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/SMI/2005/WindowsSettings Embedded OLE package script
- http://schemas.openxmlformats.org/drawingml/2006/mainIn document text (OLE body)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_office_00002c67.exe |
embedded-pe | Office MZ+PE at offset 0x2C67 | 39321 bytes |
SHA-256: f3d4e44793eb6911f77a128c7aa7608bc65ab9dc7daca7fe5ba50d71bfe35df3 |
|||
ole10native_00.bin |
ole-package | OLE Ole10Native stream: ObjectPool/_1572084892/Ole10Native | 31511 bytes |
SHA-256: 27b1184d4767c5478f846eacf62dc6d3f68e41ed0a09e6cdbd7b896e288b73d9 |
|||
ole10native_00_calc.exe |
ole-package-payload | OLE Ole10Native payload: ObjectPool/_1572084892/Ole10Native; display_name=calc.exe; full_path=C:\Users\xxxxx\AppData\Local\Temp\calc (2).exe; temp_path=; def_file= | 31232 bytes |
SHA-256: c74f41325775de4777000161a057342cc57a04e8b7be17b06576412eff574dc5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.