Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 dc9d38febdf38c42…

MALICIOUS

Office (OLE) / .DOC

21.5 KB Created: 2021-05-09 14:04:00 Authoring application: Microsoft Office Word
MD5: 6bca61e1bbdd312bd05369cc85f364e8 SHA-1: ac8dcc9af52f36d52621a24a005c4bcfec1c7b31 SHA-256: dc9d38febdf38c4223bbb818aef14ef1d58aafbe7a722ed479081bbcd41b4c43
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1071.001 Application Layer Compromise T1566.001 Phishing T1071.002 Remote Services - Scheduled Task

The heuristic firings, specifically `SC_STR_BITSADMIN` and `SE_LOLBIN_RUN_COMMAND`, strongly indicate the document is designed to execute `bitsadmin` with a command string. This utility is commonly abused for covert file downloads. The embedded URL points to an image, likely a visual lure. The document's structure and the use of `bitsadmin` suggest a macro-based downloader attempting to establish a foothold on the system. The document body contains a reference to `bitsadmin` and its intended use, further solidifying this assessment.

Heuristics 3

  • Reference to bitsadmin (download) high SC_STR_BITSADMIN
    Reference to bitsadmin (download)
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://rinaldomattei.firstcloudit.com/Carta_identita.jpg
    • http://schemas.openxmlformats.org/drawingml/2006/main