Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 88a3ee8d1ee2e6b4…

MALICIOUS

Office (OLE) / .DOC

973.0 KB Created: 2021-05-19 11:34:00 Authoring application: Microsoft Office Word
MD5: ace4c73a74714b6570d5632750e8a71c SHA-1: 2ec0284e3a9e09e7f41e50a1b14a9e6bb9a12141 SHA-256: 88a3ee8d1ee2e6b4a77d9f9319958bfd92cee968305f9e591fb0ecc0991dcd09
502 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File T1059.001 PowerShell

The sample contains VBA macros that automatically execute upon opening the document, leveraging the Shell() function. This macro functionality is used to launch an embedded PE executable. The presence of VirtualAlloc, VirtualProtect, LoadLibrary, and GetProcAddress API calls within the VBA code suggests the embedded executable is likely a downloader or payload that requires memory manipulation and dynamic library loading. The OLE structure also indicates potential exploitation of CVE-2026-21514.

Heuristics 14

  • Office EPRINT stream contains EMF object high CVE related OLE_EPRINT_EMF_OBJECT
    OLE ObjectPool contains an EPRINT stream with EMF data. This is rare in normal documents and is CVE-2007-3893/MS07-046-family evidence when paired with Office exploit payload anomalies, but the malformed EMF record is not proven by this rule alone.
  • OLE with Ole10Native — possible CVE-2026-21514 exploitation high CVE likely CVE_2026_21514
    Document contains a Word OLE object with Ole10Native plus executable, PE, or risky remote-link indicators. CVE-2026-21514 exploits OLE metadata validation; this stronger structure is treated as likely exploitation.
  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • Reference to VirtualProtect API medium SC_STR_VIRTUALPROTECT
    Reference to VirtualProtect API
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://schemas.openxmlformats.org/drawingml/2006/main

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
a90963d5d6c74d486b2956916b800b6ec29cbd6400e3d375efd2c0f312d5e9fa
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1426 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved macro source contains an auto-exec entry point and execution/download terms.
embedded_office_0008ec68.exe
aa8e86dc5f579af964fa7f3e5a595becb8477f2e9830c984a7adfe8cde3a45ae
embedded-pe Office MZ+PE at offset 0x8EC68 411544 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
ole10native_00.bin
91fc96e8a83a6fc59cd5a66fdc23ac41c525c00035ce1a1563bfaee3868a7675
ole-package OLE Ole10Native stream: ObjectPool/_1682904170/Ole10Native 385306 bytes