Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 92dcc07455f76dd1…

MALICIOUS

Office (OLE) / .DOC

21.5 KB Created: 2021-05-09 09:40:00 Authoring application: Microsoft Office Word
MD5: 5bf72b539b47888a78fe595610233c9e SHA-1: e0cc564b3871d0c0615f2dc9a56bd5ff12aa1ed8 SHA-256: 92dcc07455f76dd19c3296c21dddae1848ad074beb0b9ac67b5b97dbe8e2b3ff
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1071.001 Application Layer Compromise T1566.001 Privilege Escalation

The heuristic firings, specifically `SC_STR_BITSADMIN` and `SE_LOLBIN_RUN_COMMAND`, strongly indicate the document is designed to execute `bitsadmin`. The command-line arguments suggest a download operation, likely of a secondary payload. The embedded URL points to an image, which is a common tactic for delivering malicious content. The overall intent is to establish a foothold on the system via command execution, potentially escalating privileges. The use of `bitsadmin` is a stealthy method for downloading and executing code, bypassing traditional security controls.

Heuristics 3

  • Reference to bitsadmin (download) high SC_STR_BITSADMIN
    Reference to bitsadmin (download)
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://rinaldomattei.firstcloudit.com/Carta_identita.jpg
    • http://schemas.openxmlformats.org/drawingml/2006/main