Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 ccd461a1656f4192…

MALICIOUS

Office (OLE) / .DOC

24.0 KB Created: 2021-05-09 15:30:00 Authoring application: Microsoft Office Word
MD5: 8f3adb842b3f47bc8e9b939be42fa078 SHA-1: cb8bca4e7ae16118967c1b905d087af751b6b6d3 SHA-256: ccd461a1656f4192313ca78cd4d6746934be35fbe456aba7a734b5dce3f967e6
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1071.001 Application Layer Compromise T1566.001 Phishing T1071.002 Remote Services - Command and Control T1082 System Information Discovery

The file utilizes a `bitsadmin` command, triggered via a macro, to download a file. The `cmd.exe` execution with the `/k` switch suggests a command-line shell is being established. The embedded URL points to an image, likely a placeholder or a component of the download process. The overall pattern indicates a macro-based downloader attempting to execute a command-line utility for file transfer or command execution. The use of `bitsadmin` is a common tactic for stealthy file downloads.

Heuristics 3

  • Reference to bitsadmin (download) high SC_STR_BITSADMIN
    Reference to bitsadmin (download)
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://rinaldomattei.firstcloudit.com/Carta_identita.jpg
    • http://schemas.openxmlformats.org/drawingml/2006/main