Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 ccce655f63bafeea…

MALICIOUS

Office (OLE)

4.48 MB Created: 2006-02-01 11:10:36 Authoring application: Advanced Installer 7.1.3
MD5: 7441f90ac827f200d3ac94d54a1d0208 SHA-1: 7aee7d5f2476743b37433dce39e719c1a9b73ec4 SHA-256: ccce655f63bafeea7d2811158a1abf3bd552c87df15d241f50e19f429133ec99
142 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1105 Ingress Tool Transfer

The sample is an Office document containing an embedded PE executable, identified by the OLE_EMBEDDED_EXE heuristic. The document body lists several files, including 'ReplaceMagic.exe' and 'RMThreadKiller.exe', suggesting a lure related to system utilities or cleanup. The presence of CreateProcess and ShellExecute API references indicates the document likely attempts to launch the embedded executable. The embedded executable is the primary payload, and the URLs associated with 'replacemagic.com' are likely related to the distribution or command and control infrastructure.

Heuristics 5

  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Reference to CreateProcess API high SC_STR_CREATEPROCESS
    Reference to CreateProcess API
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.replacemagic.com/post.aspx[HttpPostUrl]ErrorRetryecmusReinstallModeErrorAbortAppsShutdownOption
    • http://www.replacemagic.com/RMPowerPointEdition.aspxARPURLINFOABOUTchangesCtrlEvtchanges&Next
    • http://www.replacemagic.com/contact.aspxARPCONTACTOLDPRODUCTS;AI_NEWERPRODUCTFOUNDSecureCustomProperties&ResumeButtonText_Resume&YesButtonText_YesSetup
    • http://www.replacemagic.com/forumARPHELPLINKButtonText_OKErrorDialogTypical&NoButtonText_NoexclamicExclamationIcon&ReturnButtonText_Return&FinishButtonText_Finish&RepairButtonText_RepairChangingCtrlEvtChanging&IgnoreButtonText_Ignorehttp://www.replacemagic.com/Downloads.aspxARPURLUPDATEINFORepairingCtrlEvtRepairingremovesCtrlEvtremovesPPROMPTROLLBACKCOSTButtonText_CancelEnableUserControlProductVersion3CTRLSAI_APP_FILE2ALLUSERSLogo.exeARPPRODUCTICONAxmataManufacturer&RemoveButtonText_RemoveINSTALLLEVEL(+1)-970-672-0200ARPHELPTELEPHONE{\DlgFontBold8}DlgTitleFontAI_UPGRADE
    • http://www.example.com
    • http://www.yahoo.com
    • http://www.google.com

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_00023800.exe
ead8f0bd8210e53360741e2d918bf648b35d7cd90420e7a792c6fa89eaaa9b36
embedded-pe Office MZ+PE at offset 0x23800 4555776 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.72, consistent with packed or encrypted content.