MALICIOUS
60
Risk Score
Malware Insights
MITRE ATT&CK
T1204 Malicious Link
T1204.002 Malicious Link: Malicious File
T1059 Command and Scripting Interpreter
T1566 Phishing
T1566.001 Phishing: Spearphishing Attachment
The file is an Excel spreadsheet containing an embedded OLE object, specifically identified as a Microsoft Equation Editor object. This is a known vector for exploiting vulnerabilities like CVE-2017-11882, which allows for arbitrary code execution. The embedded object is the primary indicator of malicious intent, suggesting the file is designed to deliver a secondary payload.
Heuristics 2
-
Equation Editor OLE object high OLE_EQUATION_EDITOREmbedded OLE object xl/embeddings/g5GDl6d.noKlXAq contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
-
Embedded OLE object medium OOXML_OLE_OBJECTDocument contains an embedded OLE object
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
ooxml_oleobject_00.binf560b182cbbddd9a63a5d781927d6915a0f3dac015fb49fb1a7b3db48a52cf33 |
ooxml-ole-object | OOXML embedded OLE part: xl/embeddings/g5GDl6d.noKlXAq | 991744 bytes |
ooxml_oleobject_00_ole10native_00.bind211b1e591bbbce9cdc374a7430d34112965337a00fd7697170aa6a5d90a96d5 |
ole-package | OOXML xl/embeddings/g5GDl6d.noKlXAq Ole10Native stream: ole10natiVE | 981003 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.