Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 8e53218b87870521…

MALICIOUS

Office (OLE)

102.1 KB Created: 1996-12-17 01:32:42 Authoring application: Microsoft Excel
MD5: d5ebe19d314cc5a1698fd68ef55c6905 SHA-1: be5c836027c1e2e860281d0c429901caa3615e11 SHA-256: 8e53218b878705210bcc8b0b136b539bbe11c4e284a1eb05ed9a1d831dd51a2a
180 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution

The file is an Excel document that triggers a critical vulnerability (CVE-2009-3129) related to FEATHEADER record overflow. This exploit likely leads to the execution of arbitrary code. The presence of a NOP sled and PEB access further indicates shellcode execution. While the document body is minimal, the exploit itself suggests an attempt to compromise the user's system, potentially for further payload delivery, as indicated by the embedded URLs.

Heuristics 5

  • CVE-2009-3129 — Excel FEATHEADER record overflow critical CVE exact CVE_2009_3129
    Workbook BIFF stream contains a FEATHEADER (Feature Header) record with anomalous size (record_size=22, isf=4, cbHdrData=4). Legitimate FEATHEADER records are tiny (<100 bytes) and carry cbHdrData values that fit in the record body; the value here is the documented CVE-2009-3129 exploit primitive — cbHdrData drives a memcpy with attacker-controlled size, leading to memory corruption and code execution in Excel 2007/2003.
  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • PEB access via FS segment (x86) high SC_PEB_ACCESS
    PEB access via FS segment (x86)
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 104,510 bytes but its declared streams total only 24,565 bytes — 79,945 bytes (76%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.pdf-repair.com
    • http://www.pdf-repair.com)/Producer(Advanced
    • http://www.pdf-repair.com)/ModDate(D:20100406171120+08
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/