Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 31f10d41e6ea7fd5…

MALICIOUS

Office (OLE)

227.0 KB Created: 2006-01-25 08:30:00 Authoring application: Microsoft Office Word
MD5: 835b16d1503c8f583c01568a3c6508a7 SHA-1: 71523703194f29b7995b1f77bbf25d7917cb237c SHA-256: 31f10d41e6ea7fd5ac0c4daa9a0f1a7358740dfbe463c326506a9dc5c1ccfc02
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1071.001 Web Protocols

The OLE document exhibits a large slack space anomaly, suggesting embedded malicious content. Heuristics indicate the use of LoadLibrary and VirtualProtect APIs, common in malware for loading and executing code. While no specific document body content or scripts were extracted, the presence of these API calls and an unknown reputation URL points towards a malicious downloader attempting to exploit a vulnerability within the Office application to fetch and run a secondary payload.

Heuristics 4

  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 232,445 bytes but its declared streams total only 21,151 bytes — 211,294 bytes (91%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Reference to VirtualProtect API medium SC_STR_VIRTUALPROTECT
    Reference to VirtualProtect API
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0
    • http://www.southasiaanalysis.org/papers37/paper3604.html
    • http://crl.verisign.com/ThawteTimestampingCA.crl0
    • http://crl.verisign.com/tss-ca.crl0
    • https://www.verisign.com/rpa
    • https://www.verisign.com/rpa01
    • http://crl.verisign.com/pca3.crl0
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
    • https://www.verisign.com/rpa0
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0
    • http://www.acdsee.com