Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 c6ae94eea18ddfae…

MALICIOUS

Office (OLE)

181.9 KB Created: 2001-12-14 14:26:00 Authoring application: Microsoft Word 9.0
MD5: 6a3674bf66012fb88388b4e6c1921148 SHA-1: 4e4e798f0bee920e1adf134db5a55c6be46b37bf SHA-256: c6ae94eea18ddfae157c21bbdda3cbee0efaffb9a93e8d75a2b714532ff2d90e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The file is identified as malicious due to a critical heuristic firing for CVE-2006-6456, indicating exploitation of a malformed table structure in Microsoft Word. While VBA macros could not be extracted due to an unsupported format, the OLE slack anomaly suggests potential obfuscation or padding. The document body contains heavily garbled text, offering no clear user-facing lure. The primary attack vector appears to be the exploitation of the CVE-2006-6456 vulnerability.

Heuristics 3

  • CVE-2006-6456 — Microsoft Word malformed table SPRM critical CVE exact CVE_2006_6456
    WordDocument contains a malformed table border-color SPRM in the CVE-2006-6456 shape: a valid table-SPRM cluster is followed by an invalid high-byte 0xFF SPRM where Word expects a normal sprmTBrc*Cv record. Vulnerable Word 2000/2002/2003 parsers corrupt memory while handling this malformed data structure.
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 186,220 bytes but its declared streams total only 94,801 bytes — 91,419 bytes (49%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Unsupported Office format for VBA extraction info OFFICE_FORMAT_UNSUPPORTED
    olevba could not extract VBA macros (PermissionError); format-agnostic byte-level scans still ran. Likely legacy, encrypted, or malformed OLE/OOXML — re-scanning the same bytes will yield the same outcome.