Malicious Office (OLE) / .TMP — malware analysis report

Static analysis result for SHA-256 d0d3d04537f2619e…

MALICIOUS

Office (OLE) / .TMP

193.0 KB Created: 2009-03-23 02:20:00 Authoring application: Microsoft Office Word
MD5: 003f6cf9c1d01d1b7e2e585293ec514e SHA-1: 3d68e337e2e8ad065fe64625601ed8b5b217b7f6 SHA-256: d0d3d04537f2619ed886d91f7925717af6edb011b88fe4c5ce8d3574f416a4e9
140 Risk Score

Malware Insights

The sample is an OLE document with a high percentage of slack space, indicating potential obfuscation. Heuristics indicate the presence of XOR-encoded strings and a GetPC stub, common techniques for hiding malicious code. While no specific document body or scripts were extracted, these indicators suggest the file is designed to execute arbitrary code, likely as a downloader or dropper.

Heuristics 3

  • XOR-encoded strings (key 0x63) critical SC_XOR_ENCODED
    Found 3 Windows library/API name(s) XOR-encoded with single-byte key 0x63: 'CreateProcessA', 'ExitProcess', 'CreateFileA'
  • x86 GetPC stub (CALL $+5; POP EAX) high SC_GETPC_CALL
    x86 GetPC stub (CALL $+5; POP EAX)
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 197,633 bytes but its declared streams total only 20,639 bytes — 176,994 bytes (90%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).