MALICIOUS
60
Risk Score
Malware Insights
MITRE ATT&CK
T1559.001 Component Object Model Hijacking
The file is an Excel spreadsheet containing an embedded OLE object identified as Equation Editor. This is a high-severity finding and a common technique used to exploit vulnerabilities in Microsoft Office applications. The embedded object is likely a malicious payload designed to be executed when the document is opened or interacted with. No specific family could be identified, but the technique is well-established for initial compromise.
Heuristics 2
-
Equation Editor OLE object high OLE_EQUATION_EDITOREmbedded OLE object xl/embeddings/xz.uYqCip9 contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
-
Embedded OLE object medium OOXML_OLE_OBJECTDocument contains an embedded OLE object
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
ooxml_oleobject_00.bin9d2787826d6e0b89a9318488167960026534a7ae4d659f739c66d4e7a74495a0 |
ooxml-ole-object | OOXML embedded OLE part: xl/embeddings/xz.uYqCip9 | 844800 bytes |
ooxml_oleobject_00_ole10native_00.binc3acf0ed37827f40659b14581b478a7dacf90f53edcdf3486e2e6853bd189670 |
ole-package | OOXML xl/embeddings/xz.uYqCip9 Ole10Native stream: oLe10naTivE | 835734 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.