Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 65b0a9d035e5cf98…

MALICIOUS

Office (OLE)

3.56 MB Created: 2010-06-08 12:13:00 Authoring application: Microsoft Office Word First seen: 2026-05-11
MD5: eddbc68e4376cc07642c7e9543eb6fe8 SHA-1: 65870b601afec50df37869e2ede367528cb17d9e SHA-256: 65b0a9d035e5cf98a0e828a86f69ad0872ca9de1c0abe86186df6cd36312f9c2
362 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1059.001 PowerShell

The document exhibits social engineering lures, including a 'ClickFix' attack and a travel support phone scam, to trick users into executing commands. Heuristics indicate suspicious invocation of cmd.exe and references to Windows Script Host, suggesting the potential execution of malicious scripts or payloads. The presence of a PHP webshell heuristic points towards a backdoor capability, likely intended to download and execute further stages.

Heuristics 9

  • PHP webshell / backdoor source critical WEBSHELL_PHP
    The file contains PHP server-side code with the signature of a webshell/backdoor (request input fed to a command/code-exec sink with a decoder/second sink (RCE backdoor)). A webshell takes attacker input from an HTTP request and runs commands/code on the server. Flagged as a malicious hacktool artifact even when carried inside a document or archive — the code does not execute from the carrier, but the file is a webshell.
  • Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Logo-00.png In document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/1/1b/Logo-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Intro-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/a/ae/Intro-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Additional_services_01.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/5/5a/Additional_services_01.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Additional_services_02.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/f/f6/Additional_services_02.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Additional_services_03.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/d/d4/Additional_services_03.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Additional_services_04.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/d/d8/Additional_services_04.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Additional_services_05.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/f/f6/Additional_services_05.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_01.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/e/ed/Sql_express_01.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_02.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/3/35/Sql_express_02.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_03.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/9/96/Sql_express_03.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_04.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/8/87/Sql_express_04.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_05.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/b/be/Sql_express_05.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_06.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/d/d3/Sql_express_06.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Sql_express_07.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/f/fc/Sql_express_07.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_01.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/3/3c/Webapp_01.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_02.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/6/65/Webapp_02.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_03.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/d/df/Webapp_03.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_04.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/c/c8/Webapp_04.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_05.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/0/06/Webapp_05.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_06.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/d/db/Webapp_06.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_07.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/5/51/Webapp_07.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Webapp_08.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/4/45/Webapp_08.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Msfcon-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/8/86/Msfcon-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/Archivo:Msfcli-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/images/3/30/Msfcli-00.pngIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/MsfguiIn document text (OLE body)
    • http://www.metasploit-es.com.ar/wiki/index.php/MsfwebIn document text (OLE body)
    +244 more URL(s)