Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 e34f810e518ae9d5…

MALICIOUS

Office (OLE)

137.9 KB Created: 2018-10-04 17:22:00 Authoring application: Microsoft Office Word First seen: 2019-01-20
MD5: 29399f085ecc41f1854cefe6bae2c8b2 SHA-1: e1d06bc4dadd311322a0151affbe584b53e6ad4e SHA-256: e34f810e518ae9d5fc11b794e2ce718d0ebcf82895c2c1600f0cbefb1dbd31a7
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is detected as malicious by ClamAV with a signature indicating a malicious document. Although VBA macros could not be extracted due to an unsupported format, the presence of an embedded URL and the general nature of malicious Office documents suggest an attempt to trick the user into executing malicious content, likely via a spearphishing attachment.

Heuristics 3

  • ClamAV: Doc.Malware.00536d-6707473-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Malware.00536d-6707473-0
  • Unsupported Office format for VBA extraction info OFFICE_FORMAT_UNSUPPORTED
    olevba could not extract VBA macros (AssertionError); format-agnostic byte-level scans still ran. Likely legacy, encrypted, or malformed OLE/OOXML — re-scanning the same bytes will yield the same outcome.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)