Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 9e3ad91b1bec76e3…

MALICIOUS

Office (OLE) / .DOC

75.0 KB Created: 2007-09-18 04:34:00 Authoring application: Microsoft Word 11.
MD5: 8b450c4dddf2baa5ad7ee39bbe31b633 SHA-1: 59798d24702ced091054cc44d20dd34d57a605de SHA-256: 9e3ad91b1bec76e3b6d7adc6833b5cc13caa166a68e905018e46a9bea424121d
80 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The OLE document exhibits a large slack space anomaly, indicative of embedded malicious content. The presence of multiple embedded URLs, primarily pointing to eastturkistan.tv and related domains, suggests a potential lure or command-and-control infrastructure. The PEB access heuristic indicates attempts to interact with the process environment, often used for evasion or payload execution. While no scripts were directly extracted, the combination of these factors strongly suggests the document is designed to exploit a vulnerability and download a secondary payload.

Heuristics 3

  • PEB access via FS segment (x86) high SC_PEB_ACCESS
    PEB access via FS segment (x86)
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 76,800 bytes but its declared streams total only 16,486 bytes — 60,314 bytes (79%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.eastturkistan.tv/
    • http://www.eastturkistan.tv/STRT-2/
    • http://www.eastturkistan.tv/STRT-6/
    • http://www.eastturkistan.tv/STRT-7/
    • http://www.eastturkistan.tv
    • http://www.eastturkistan.net/
    • http://www.sherqiyturkistan.net/
    • http://www.sherqiyturkistan.org/
    • http://schemas.openxmlformats.org/drawingml/2006/main