Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 67c9bdec991699fd…

MALICIOUS

Office (OLE) / .DOC

1.85 MB Created: 2009-03-18 12:29:00 Authoring application: Microsoft Office Word
MD5: a0317cdb3c62ee79622209de118871b8 SHA-1: 895024b85fbffe5921e027c4a5b3656646d6d3aa SHA-256: 67c9bdec991699fdb7521f5cd0ecaa1fa1ba7ec5523ea96b1ee9adfa2d0f9714
304 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1140 Deobfuscate/Decode Files or Information T1027 Obfuscated Files or Information

The sample is a Microsoft Office document that contains an embedded PE executable, identified by the 'OLE_EMBEDDED_EXE' heuristic. The 'OFFICE_PACKAGE_RISKY_FILE' and 'SE_PASSWORD_ARCHIVE_LURE' heuristics indicate that this embedded executable is likely intended to be delivered as a password-protected archive, a common tactic to evade initial security analysis. The presence of VirtualAlloc, LoadLibrary, and GetProcAddress API calls suggests the embedded executable is designed to load and execute code dynamically.

Heuristics 9

  • OLE with Ole10Native — possible CVE-2026-21514 exploitation high CVE likely CVE_2026_21514
    Document contains a Word OLE object with Ole10Native plus executable, PE, or risky remote-link indicators. CVE-2026-21514 exploits OLE metadata validation; this stronger structure is treated as likely exploitation.
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Ole10Native package drops an auto-executable payload critical OFFICE_PACKAGE_RISKY_FILE
    OLE Package displayName or fullPath ends in a directly auto-executable extension (a runnable binary or a script the default shell host runs on double-click). Embedding such a payload inside an Office document has no benign authoring use — it is a malware-delivery dropper.
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cisco.partnerelearning.com/Saba/Web/Main
    • http://tftpd32.jounin.net
    • https://kcteam.emea.eds.com/sites/1388/GNE-intern/Technics/documents/Internal_Training
    • https://knowledgecentre.eds.com/sites/kc6/c3/Shared%20Documents/Export%20Compliance%20Position%20-%20Capability%20Documents.doc
    • https://knowledgecentre.eds.com/Export
    • http://gn.iweb.eds.com/software/
    • http://www.cisco.com/en/US/products/ps6441/products_command_reference_chapter09186a00804ab444.html
    • http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a00800a67f5.shtml
    • http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080093f33.shtml
    • http://www.heise.de/netze/lib/netzwerk-rechner.shtml
    • http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/index.htm
    • http://www.cisco.com/en/US/docs/routers/access/2600/hardware/installation/guide/2600ch1.html
    • http://www.cisco.com/public/support/tac/tools.shtml
    • https://knowledgecentre.eds.com/sites/kc6/default.aspx
    • https://knowledgecentre.eds.com/sites/kc6/c3/Shared%20Documents/Network_Glossary.htm
    • http://de.wikipedia.org/wiki/OSI-Modell
    • http://de.wikipedia.org/wiki/Address_Resolution_Protocol
    • http://de.wikipedia.org/wiki/Kollisionsdom%C3%A4ne
    • http://de.wikipedia.org/wiki/Broadcast-Dom%C3%A4ne
    • http://www.cisco.com/en/US/products/hw/switches/ps633/products_user_guide_chapter09186a008007efc8.html
    • http://www.cisco.com/en/US/products/hw/routers/ps341/products_tech_note09186a00801a886f.shtml
    • http://de.wikipedia.org/wiki/Crosskabel
    • http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a00801f5d8f.shtml
    • http://www.cisco.com/en/US/products/hw/routers/ps214/products_tech_note09186a00801f5d87.shtml
    • http://www.cisco.com/en/US/products/hw/routers/ps274/products_tech_note09186a00800b0858.shtml
    • http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_configuration_example09186a0080204528.shtml
    • http://www.cisco.com/en/US/docs/ios/interface/command/reference/ir_c2.html
    • http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00800b1500.shtml
    • http://www.cisco.com/en/US/tech/tk389/tk621/technologies_tech_note09186a008009482f.shtml
    • http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_dhcp_svr_cfg_ps9587_TSD_Products_Configuration_Guide_Chapter.html
    • http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_dhcp_client_ps9587_TSD_Products_Configuration_Guide_Chapter.html
    • http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_dhcp_rly_agt_ps9587_TSD_Products_Configuration_Guide_Chapter.html
    • http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a008022493f.shtml
    • http://www.cisco.com/en/US/tech/tk389/tk689/technologies_configuration_example09186a0080890607.shtml
    • http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/5.x/configuration/guide/channel.html
    • http://www.cisco.com/en/US/docs/switches/lan/catalyst2900xl_3500xl/release12.0_5_xp/eeswcfg/masctrnk.html
    • http://standards.ieee.org/getieee802/download/802.1Q-2003.pdf
    • http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/8.x/configuration/guide/sec_port.html
    • http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_acl_ov_guideline_ps6350_TSD_Products_Configuration_Guide_Chapter.html
    • http://www.cisco.com/en/US/tech/tk389/tk214/technologies_tech_note09186a0080094781.shtml
    • http://www.cisco.com/en/US/docs/switches/lan/catalyst2950/hardware/installation/guide/hgovrev.html
    • http://de.wikipedia.org/wiki/Medium_Dependent_Interface
    • http://de.wikipedia.org/wiki/RS232
    • http://cnx.org/content/m12293/latest/
    • http://www.cisco.com/en/US/docs/ios/preface/usingios.html
    • http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008010e9d5.shtml
    • http://tools.ietf.org/html/rfc1918
    • http://de.wikipedia.org/wiki/Private_IP-Adresse
    • http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_tech_note09186a00800a6057.shtml
    • http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080093f22.shtml
    +33 more URL(s)

Extracted artifacts 21

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_0008989a.exe
1e2c13ce12c130923aa4dd7c0c82fe53dfae209929c06a87cdcb752f2f37d2f9
embedded-pe Office MZ+PE at offset 0x8989A 1373030 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.62, consistent with packed or encrypted content.
ole10native_00.bin
5068fbdee33bafde7e84b7a6377c4197f12ba6f1510093a0fb26402443210070
ole-package OLE Ole10Native stream: ObjectPool/_1235990337/Ole10Native 1704 bytes
ole10native_01.bin
27a0b8f07b8a42fa51ded003c13e6f8aad8babeae6cd2321117979af6773e109
ole-package OLE Ole10Native stream: ObjectPool/_1235992131/Ole10Native 1077 bytes
ole10native_02.bin
b7181ca9f626afee964926203e0648ba939f9c42b937b2e2c4441b5178979ccd
ole-package OLE Ole10Native stream: ObjectPool/_1236080524/Ole10Native 1667 bytes
ole10native_03.bin
d03f0ab8d06125ffce4b06aa4cf97e2054608c698d3d1f10191b9e1d8741e5d0
ole-package OLE Ole10Native stream: ObjectPool/_1236493050/Ole10Native 1030 bytes
ole10native_04.bin
805f284f1b09f8cba7bf87b68813adf63fe014ab706e9d6bfa544fb82daa440b
ole-package OLE Ole10Native stream: ObjectPool/_1236493141/Ole10Native 3107 bytes
ole10native_05.bin
3e7fd20fbc203e49390fbfbc30a98225aef2023c3372d69c00d16dfa516c8333
ole-package OLE Ole10Native stream: ObjectPool/_1236498606/Ole10Native 2303 bytes
ole10native_06.bin
93f7cea4f04bce250e370adbdaf2921ffb9df0a2c94f27be45e0e8de4586e365
ole-package OLE Ole10Native stream: ObjectPool/_1236624316/Ole10Native 1640 bytes
ole10native_07.bin
050c835318859635ec55b167ff03426bddb85da18f53cf9b0ec945ec95d8ef1c
ole-package OLE Ole10Native stream: ObjectPool/_1236664110/Ole10Native 2361 bytes
ole10native_08.bin
63a85b7dcc7f8c43f41eed15cfec474f522bc8349048d243039c6567563d1d42
ole-package OLE Ole10Native stream: ObjectPool/_1236664332/Ole10Native 3408 bytes
ole10native_09.bin
a33261cca65ec5d4f331aff00ee2e193895963181e2ff35e45f5a32e8a45521c
ole-package OLE Ole10Native stream: ObjectPool/_1236664473/Ole10Native 3959 bytes
ole10native_10.bin
7cb18cfa87cc1583ff92584b83808004e79dee28b8b9a52f5914c49018d88aa7
ole-package OLE Ole10Native stream: ObjectPool/_1236666283/Ole10Native 2379 bytes
ole10native_12.bin
73a483898816d6edc6d2932dd70398803bffec63ce169f9478a35ccf1a1d2f96
ole-package OLE Ole10Native stream: ObjectPool/_1236666355/Ole10Native 1403 bytes
ole10native_13.bin
dca84607b37114a8a854a8535dc75a2631cbe6ce33f527df52aedfadf4de4425
ole-package OLE Ole10Native stream: ObjectPool/_1236666810/Ole10Native 1851 bytes
ole10native_14.bin
2b31586902fb53743a048d0484f63faf934d7fd16828c91e926a17a005cdf33f
ole-package OLE Ole10Native stream: ObjectPool/_1236667962/Ole10Native 1849 bytes
ole10native_15.bin
19f76fcff929990d44609d62b2918b7eaaf8351d4b28b85d14ec06d766710fa2
ole-package OLE Ole10Native stream: ObjectPool/_1236668186/Ole10Native 1358 bytes
ole10native_16.bin
5bf736a4fd9c8e5369fe3a95e8e153e629b7a1a4bab51e9f31defbd987ec21cc
ole-package OLE Ole10Native stream: ObjectPool/_1236668550/Ole10Native 1852 bytes
ole10native_17.bin
e7a8f2ce8c5d717fa6a5b23ab9aed9a754ea3cc06fc661072f9ed423db5f6256
ole-package OLE Ole10Native stream: ObjectPool/_1236668899/Ole10Native 1889 bytes
ole10native_18.bin
a456ddbc2d7dab079084fa32b8ccc0c5daa82064bd6e7bc15248113355fadd61
ole-package OLE Ole10Native stream: ObjectPool/_1236671275/Ole10Native 2276 bytes
ole10native_19.bin
d69c5ff96f4bd5168195ee178707d45cd32e7c92be467cb6cfe3104bd9a4967a
ole-package OLE Ole10Native stream: ObjectPool/_1236671276/Ole10Native 2203 bytes
ole10native_20.bin
64d769b7fde991bdd62494a3d2b182bfdb38c1452721050e8f3bd46597df13d6
ole-package OLE Ole10Native stream: ObjectPool/_1298959048/Ole10Native 114844 bytes