Malicious Office (OLE) / .MST — malware analysis report

Static analysis result for SHA-256 7406d20c28191f23…

MALICIOUS

Office (OLE) / .MST

1.18 MB Created: 2006-02-01 11:10:38 Authoring application: Windows Installer
MD5: c1db9448abd98339f211e531308b5d81 SHA-1: a8970601cfc5b67f311347368996abecaf6b32c8 SHA-256: 7406d20c28191f23359ade5d2281c1a833b77ddf186d29281c4ac2cd1fadcfd8
262 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1105 Ingress Tool Transfer

The file is identified as malicious and contains an embedded PE executable. Heuristics indicate the use of Windows APIs such as CreateProcess and ShellExecute, suggesting the embedded executable is intended to be run. The presence of an embedded executable strongly points towards a downloader or dropper functionality.

Heuristics 8

  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Reference to CreateProcess API high SC_STR_CREATEPROCESS
    Reference to CreateProcess API
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • Reference to VirtualProtect API medium SC_STR_VIRTUALPROTECT
    Reference to VirtualProtect API
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.spikko.comButtonText_No&NoCtrlEvtchangeschangesExclamationIconexclamicWindowsType9XWindows
    • http://schemas.microsoft.com/office/word/2003/wordml}}\paperw11906\paperh16838\margl1800\margr1800\margt1440\margb1440\gutter0\rtlsect\rtlgutter
    • http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_00032200.exe
6b7596d2f04c23f5ed8a0fdda1fb6a7736351afeafea0ae1eaddf61ecc2589bc
embedded-pe Office MZ+PE at offset 0x32200 1032704 bytes