Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 c82724520ee5ffbc…

MALICIOUS

Office (OOXML) / .DOC

55.6 KB Created: 2021-08-30 16:15:00 UTC Authoring application: Microsoft Office Word 15.0000 First seen: 2022-02-19
MD5: 1366fe4e4808e4429d2424365eaf9803 SHA-1: 8a9b7cf10a66d16ef67ab8962306c026cb57879a SHA-256: c82724520ee5ffbcc6ee13c76d004aa903c2f70c93c505df87fe46e5e8cc53a9
102 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: Malicious Link T1559.001 Component Object Model Hijacking: Component Object Model Hijacking T1059.003 Command and Scripting Interpreter: Windows Command Shell

The file contains an embedded OLE object, specifically identified as a Microsoft Equation Editor object. High-severity heuristics indicate that this object is anomalous and exploits CVE-2018-0798. This suggests the document is designed to leverage this vulnerability to execute arbitrary code upon opening. No scripts were extracted, and the document body was truncated, limiting further analysis of the payload.

Heuristics 4

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object word/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • CVE-2018-0798 — anomalous Equation Editor native stream high CVE likely CVE_2018_0798_EQUATION_NATIVE_ANOMALY
    Embedded Equation Editor OLE data contains anomalous native stream bytes consistent with a CVE-2018-0798-style Equation Editor exploit. This is treated as likely CVE evidence because the Equation object is malformed and payload-like, but it does not match the exact public matrix-overflow byte signature.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
e852c191b3297087ca757e702d44e5157be7233a0e1ce4eaa0143fce35cd0ff8
ooxml-ole-object OOXML embedded OLE part: word/embeddings/oleObject1.bin 3584 bytes
ooxml_oleobject_00_ole10native_00.bin
e4f7860b13bdc97ef80721fb6b43981a57352d52e66899c58cca34bae8deeda7
ole-package OOXML word/embeddings/oleObject1.bin Ole10Native stream: olE10NatIve 1227 bytes