Win.Trojan.Delf-7648947-0 — Office (OLE) / .DOC malware analysis

Static analysis result for SHA-256 70b797b56b0170de…

MALICIOUS

Office (OLE) / .DOC

700.0 KB Created: 2012-09-21 09:56:09 Authoring application: Windows Installer
MD5: 0b38cc7346a40af26181436fd33df803 SHA-1: 2e169d5cabf238e9bfa27faf4a2137b748f4afca SHA-256: 70b797b56b0170dec899259e0c4be31fc950032fea88885393c859e3c637ceb3
340 Risk Score

Malware Insights

Win.Trojan.Delf-7648947-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is identified as malicious by ClamAV with the signature Win.Trojan.Delf-7648947-0. Static analysis revealed an embedded PE executable, indicating it functions as a dropper. Heuristics also indicate the presence of Metasploit reverse shellcode and API calls commonly used for payload execution and loading, such as VirtualAlloc and LoadLibrary.

Heuristics 7

  • Metasploit reverse_tcp shellcode critical SC_MSF_REVERSE
    Metasploit reverse_tcp shellcode
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • ClamAV: Win.Trojan.Delf-7648947-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Delf-7648947-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_00006000.exe
4216c0733609783aa75817f60bdb63d57e1a2af4c6602055d029d548e4149a11
embedded-pe Office MZ+PE at offset 0x6000 692224 bytes
Detection
ClamAV: Win.Trojan.Delf-7648947-0
Obfuscation or payload: unlikely