Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 7e36635e23c9612b…

MALICIOUS

Office (OLE) / .XLS

77.6 KB Created: 1996-12-17 01:32:42 Authoring application: Microsoft Excel
MD5: 23a6f4753bf2cf496071e781a1237b43 SHA-1: db8d2eb99f3b4a10f2c97177a01b8475f335de1a SHA-256: 7e36635e23c9612b26852e9f0bc81dd21569b79be81edd5a57aa4f8a267b8a7e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell

The sample exhibits a large slack space anomaly, indicative of hidden data. A suspicious cmd.exe invocation with an execution flag was detected, suggesting the execution of a command. The PEB access heuristic further supports the possibility of malicious code execution. While no document body or scripts were directly analyzed for intent, the combination of these heuristics points towards a downloader or initial execution stage.

Heuristics 4

  • PEB access via FS segment (x86) high SC_PEB_ACCESS
    PEB access via FS segment (x86)
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 79,481 bytes but its declared streams total only 24,565 bytes — 54,916 bytes (69%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.pdf-repair.com
    • http://www.pdf-repair.com)/Producer(Advanced
    • http://www.pdf-repair.com)/ModDate(D:20100406171120+08
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/