Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 2b53b127efec606a…

MALICIOUS

Office (OLE)

226.7 KB
MD5: 050d887453897fa47127b4eacdf94b24 SHA-1: 5d18de180404a0dc62d8f884299826cb2d6cdf48 SHA-256: 2b53b127efec606abade30a8c2e7e03aa23e8684e9a13ace874c3c59492add64
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious File T1059 Command and Scripting Interpreter

The file is an OLE document that triggers a critical heuristic for CVE-2009-3129, indicating an exploit targeting a Microsoft Excel FEATHEADER record overflow. This vulnerability allows for arbitrary code execution. The large slack space in the OLE structure is also anomalous. No document body, scripts, or URLs were extracted, but the exploit itself is sufficient to classify the attack pattern.

Heuristics 2

  • CVE-2009-3129 — Excel FEATHEADER record overflow critical CVE exact CVE_2009_3129
    Workbook BIFF stream contains a FEATHEADER (Feature Header) record with anomalous size (record_size=22, isf=4, cbHdrData=4). Legitimate FEATHEADER records are tiny (<100 bytes) and carry cbHdrData values that fit in the record body; the value here is the documented CVE-2009-3129 exploit primitive — cbHdrData drives a memcpy with attacker-controlled size, leading to memory corruption and code execution in Excel 2007/2003.
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 232,168 bytes but its declared streams total only 34,044 bytes — 198,124 bytes (85%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).