MALICIOUS
320
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
T1105 Ingress Tool Transfer
T1059.003 Windows Command Shell
T1204.002 Malicious File
The sample is a Microsoft Office document containing an embedded PE executable. Heuristics indicate references to CreateProcess, ShellExecute, LoadLibrary, and GetProcAddress APIs, suggesting the execution of external code. The embedded executable, 'embedded_office_00011a00.exe', is the primary indicator of malicious intent, likely serving as a dropper for further payloads.
Heuristics 9
-
Embedded PE executable critical OLE_EMBEDDED_EXEMZ/PE header found inside document — possible embedded executable
-
PEB access via FS segment (x86) high SC_PEB_ACCESSPEB access via FS segment (x86)
-
Reference to CreateProcess API high SC_STR_CREATEPROCESSReference to CreateProcess API
-
Reference to ShellExecute API high SC_STR_SHELLEXECReference to ShellExecute API
-
Reference to Windows Script Host high SC_STR_WSCRIPTReference to Windows Script Host
-
Reference to LoadLibrary API high SC_STR_LOADLIBRARYReference to LoadLibrary API
-
Reference to GetProcAddress API high SC_STR_GETPROCADDRESSReference to GetProcAddress API
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://t2.symcb.com0
- http://tl.symcd.com0&
- http://s.symcd.com06
- http://ts-ocsp.ws.symantec.com0
- http://t1.symcb.com/ThawtePCA.crl0
- http://tl.symcb.com/tl.crl0
- https://www.thawte.com/cps0/
- https://www.thawte.com/repository0W
- http://tl.symcb.com/tl.crt0
- https://www.advancedinstaller.com
- https://d.symcb.com/cps0%
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_office_00011a00.exe6249b7bf6fe2fa37c930c152dcf15f07582842ca42d4c2941c6ec9b930e2a4e3 |
embedded-pe | Office MZ+PE at offset 0x11A00 | 486400 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 18 shell/COM execution token(s).
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.