Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 5b962aefcc803956…

MALICIOUS

Office (OLE) / .DOC

6.0 KB First seen: 2022-07-05
MD5: 075760f27fb008041b542a65a616ad4f SHA-1: 73f067d8b6d704c6bcbf488980b56d957b6a89dc SHA-256: 5b962aefcc8039567472ccf993df289327bbdda101fa4f76ceae10fce21c0843
62 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample exploits CVE-2017-0199, a known vulnerability for remote code execution via specially crafted OLE objects. The embedded URL points to a secondary document, indicating a downloader pattern. The exploit likely facilitates the download and execution of a malicious payload from the specified URL.

Heuristics 2

  • OLE2Link / URL Moniker → remote loader — CVE-2017-0199 critical CVE likely CVE_2017_0199
    Document contains an embedded OLE link object whose URL Moniker points to a remote URL. When the host file is opened, Office follows the link, downloads the URL, and processes the response based on its Content-Type (HTA -> mshta.exe, RTF → Word, etc.) — the documented CVE-2017-0199 primitive. The URL extension is not a reliable filter; servers can return different payloads to Office's user agent.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://192.227.168.194/500/invc_06.doc?&otter=shaky&okra=wise&eyeball=spooky&sunshine=adorable&burn-out=willing&mixture=ludicrous&spy=gruesome&offer=damaged&sweatsuit=ashamed&sari=cowardly&motorboat=naive&maraca=chubby&musculature=dark&chair=huge&blazer=testy&pantyhose=utter&engineer=sulky&workbench=dynamic&paramedic=nosy&analyst=shaggy&distance=reminiscent&repair=burly&spleen=phobic&astrology=elated&existence=anxious&game=adaptable&clipper=swift&change=abashed&attraction=penitent&eye=gifted&step-father=abaft&hip=sable&prizefight=apathetic&litigation=damaging&pelican=enthusiastic&futon=straight&mocha=easy&sword=condemned&chart=gamy&game=moldy&desk=big&lyric=helpless&pencil=better&quarter=painstaking&galleon=gifted&diction=nauseating&asparagus=vacuous&train=combative&fortress=rebellious&shell=overjoyed&stock-in-trade=incompetent&reminder=subsequent&geometry=abrasive&average=reminiscent&finance=subdued&appendix=abounding&numeracy=nasty