Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 9cfd566336f3b24a…

MALICIOUS

Office (OLE) / .DOC

393.0 KB Created: 2007-12-03 01:19:00 Authoring application: Microsoft Word 9.0
MD5: 287644ff0660718fddc8db6fdc030a5d SHA-1: 2e807be8266bd72df89890bab4a99db4b82bcf12 SHA-256: 9cfd566336f3b24a791ddb18c07b1d3f2f6d7a8a7c744378ac3d7945c1198bbd
140 Risk Score

Malware Insights

The sample is a Microsoft Word document exhibiting several high-severity heuristic firings, including a NOP sled and XOR-encoded strings, indicative of shellcode. The large amount of slack space in the OLE structure further suggests obfuscation or embedded malicious content. While no specific exploit or payload could be identified from the static analysis, the presence of these indicators strongly suggests an attempt to exploit a vulnerability within the document itself.

Heuristics 3

  • XOR-encoded strings (key 0x95) critical SC_XOR_ENCODED
    Found 2 Windows library/API name(s) XOR-encoded with single-byte key 0x95: 'LoadLibraryA', 'GetProcAddress'
  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 402,432 bytes but its declared streams total only 16,486 bytes — 385,946 bytes (96%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).