Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 49294badb32f0de8…

MALICIOUS

Office (OLE) / .DOC

973.0 KB Created: 2021-05-19 11:36:00 Authoring application: Microsoft Office Word
MD5: 4680281474f5c31c4161ea107032b297 SHA-1: 667bee5634b77aa2657f305211f248c080dc6da0 SHA-256: 49294badb32f0de8845001dcfa55223bb4bdf916905ef3148847ab9799b4d7f1
502 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1105 Ingress Tool Transfer T1204.002 Malicious File T1027 Obfuscated Files or Information

The sample contains VBA macros that utilize the Shell() function to execute an embedded PE executable. This is a common technique for downloading and running additional malicious payloads. The presence of VirtualAlloc and VirtualProtect API calls within the VBA suggests the macro is preparing memory for execution, further supporting the payload execution hypothesis. No document body text was available for analysis, but the script behavior is clear.

Heuristics 14

  • Office EPRINT stream contains EMF object high CVE related OLE_EPRINT_EMF_OBJECT
    OLE ObjectPool contains an EPRINT stream with EMF data. This is rare in normal documents and is CVE-2007-3893/MS07-046-family evidence when paired with Office exploit payload anomalies, but the malformed EMF record is not proven by this rule alone.
  • OLE with Ole10Native — possible CVE-2026-21514 exploitation high CVE likely CVE_2026_21514
    Document contains a Word OLE object with Ole10Native plus executable, PE, or risky remote-link indicators. CVE-2026-21514 exploits OLE metadata validation; this stronger structure is treated as likely exploitation.
  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • Reference to VirtualProtect API medium SC_STR_VIRTUALPROTECT
    Reference to VirtualProtect API
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://schemas.openxmlformats.org/drawingml/2006/main

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
a90963d5d6c74d486b2956916b800b6ec29cbd6400e3d375efd2c0f312d5e9fa
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1426 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved macro source contains an auto-exec entry point and execution/download terms.
embedded_office_0008ec68.exe
90ca4ffb6edf17b0adfd07da50e4b4205ad425c7c70bb83ad69ddabfaca43f42
embedded-pe Office MZ+PE at offset 0x8EC68 411544 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
ole10native_00.bin
290a3d93613ac43b71896d93274a22e90348e64cf4830e3dccc5d81d4a3ffe6c
ole-package OLE Ole10Native stream: ObjectPool/_1682904362/Ole10Native 385306 bytes