Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 d8b522df11b4b201…

MALICIOUS

Office (OLE)

2.25 MB Created: 2008-06-11 08:16:00 Authoring application: Microsoft Office Word
MD5: 7c71108b20fa40c61142652b35774955 SHA-1: c69391916e21e679d73dbbeaf914858ded5519b9 SHA-256: d8b522df11b4b201b716ead8d55f8d115aebb6b4e3bcffd983d2513fde8bb198
128 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The document contains instructions that explicitly tell the user to copy and paste content into a command-line execution context, such as PowerShell or cmd. This is a common lure to trick users into running malicious scripts or commands. The heuristic firings for 'Clipboard command execution lure' and 'Visible LOLBin command execution instruction' strongly support this attack pattern. While no specific script was extracted, the presence of these lures and a reference to Windows Script Host suggests the document is designed to facilitate the execution of a secondary payload, likely downloaded from one of the embedded URLs.

Heuristics 5

  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.packetstormsecurity.org/viral-db/
    • http://www.packetstormsecurity.org/viral-db/AnnaKournikova.jpg.vbs.txt
    • http://www.ciac.org/ciac/bulletins/l-046.shtml
    • http://www.ethereal.com/
    • http://www.kismetwireless.net/
    • http://airsnort.shmoo.com/
    • http://new.remote-exploit.org/index.php/Auditor_main
    • http://www.cr0.net:8040/code/network/aircrack/
    • http://192.168.1.144
    • http://192.168.1.144/
    • http://virusview.net/info/virus/j&a/polymorf.html
    • http://www.vx.org.ua/vx.php?id=em11
    • http://66.102.7.104/search?q=cache:b8iU1vtk7XQJ:www.governmentsecurity.org/forum/index.php?showtopic=4726+Decompiled+Source+For+Ms+Rpc+Dcom+Blaster+Worm&hl=en
    • http://www.packetstormsecurity.org/viral-db
    • http://en.wikipedia.org/wiki/Wi-Fi
    • http://en.wikipedia.org/wiki/Wireless_LAN
    • http://en.wikipedia.org/wiki/IEEE
    • http://en.wikipedia.org/wiki/IEEE_802
    • http://en.wikipedia.org/wiki/Modulation
    • http://en.wikipedia.org/wiki/Giga
    • http://en.wikipedia.org/wiki/Hertz
    • http://en.wikipedia.org/wiki/Stream_cipher
    • http://en.wikipedia.org/wiki/RC4_(cipher
    • http://en.wikipedia.org/wiki/Confidentiality
    • http://en.wikipedia.org/wiki/CRC-32
    • http://en.wikipedia.org/wiki/Integrity
    • http://en.wikipedia.org/wiki/40-bit_encryption
    • http://en.wikipedia.org/wiki/Initialisation_vector
    • http://en.wikipedia.org/wiki/Key_management_protocol
    • http://en.wikipedia.org/wiki/Shared_key
    • http://en.wikipedia.org/wiki/2001
    • http://en.wikipedia.org/wiki/Key_(cryptography
    • http://en.wikipedia.org/wiki/Federal_Bureau_of_Investigation
    • http://en.wikipedia.org/wiki/Pseudo-random_number_generator
    • http://en.wikipedia.org/wiki/XOR
    • http://en.wikipedia.org/wiki/Vernam_cipher
    • http://en.wikipedia.org/wiki/Permutation
    • http://en.wikipedia.org/wiki/Bytes
    • http://en.wikipedia.org/wiki/Key_schedule
    • http://en.wikipedia.org/wiki/Key_length
    • http://en.wikipedia.org/wiki/Identity_(mathematics
    • http://en.wikipedia.org/wiki/Modulus
    • http://en.wikipedia.org/w/index.php?title=Scott_Fluhrer&action=edit
    • http://en.wikipedia.org/w/index.php?title=David_McGrew&action=edit
    • http://en.wikipedia.org/wiki/Nonce
    • http://en.wikipedia.org/wiki/Cryptographic_hash_function
    • http://en.wikipedia.org/wiki/HMAC
    • http://en.wikipedia.org/w/index.php?title=Itsik_Mantin&action=edit
    • http://en.wikipedia.org/wiki/Adi_Shamir
    • http://en.wikipedia.org/wiki/WEP
    +15 more URL(s)