Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 f3f6915bfab3ba2d…

MALICIOUS

Office (OLE) / .DOC

832.9 KB
MD5: 6cb49541a6e6e9508483b92646c3c333 SHA-1: 333fd84f7ff8a1b345b1eb8115533c86c85fc68e SHA-256: f3f6915bfab3ba2deeba8f1c55577b016a314192192a4ccb21ace1dee3cf90ec
80 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is a malicious OLE document containing an embedded URL that leads to an unknown domain. The presence of SC_STR_WSCRIPT heuristic suggests potential use of Windows Script Host, likely to facilitate the download and execution of a second-stage payload from the identified URL. The document body, while appearing to be a legitimate initiative definition, is likely a lure to encourage interaction with the malicious link.

Heuristics 3

  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 852,906 bytes but its declared streams total only 451,439 bytes — 401,467 bytes (47%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://doc.ecpic.gov/PortalDefault.aspx?tabindex=2&tabid=2&action=intwiz&sec_id=a6251d86-13f1-4283-824c-b201c45d9a97
    • http://schemas.microsoft.com/intellisense/ie5
    • https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0
    • http://www.macromedia.com/go/getflashplayer