MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The sample exploits CVE-2017-0199, a known vulnerability for remote code execution. The embedded URL 'http://014013123707/wiwiwiwiwiiwiwiwiwi.php' is highly suspicious and likely serves as a loader for a secondary malicious payload. This indicates a typical phishing attachment delivery mechanism.
Heuristics 2
-
OLE2Link / URL Moniker → remote loader — CVE-2017-0199 critical CVE likely CVE_2017_0199Document contains an embedded OLE link object whose URL Moniker points to a remote URL. When the host file is opened, Office follows the link, downloads the URL, and processes the response based on its Content-Type (HTA -> mshta.exe, RTF → Word, etc.) — the documented CVE-2017-0199 primitive. The URL extension is not a reliable filter; servers can return different payloads to Office's user agent.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://014013123707/wiwiwiwiwiiwiwiwiwi.php
- https://wwww.microsoft.com0
- http://en.wikipedia.org/wiki/MIT_License
- http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0Z
- http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0��
- http://www.microsoft.com/PKI/docs/CPS/default.htm0@
- http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l
- http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0
- http://www.microsoft.com/pkiops/Docs/Repository.htm0
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_001_off00016841.binf48ea04ac88d94e996724b0312c89f652abb5998d218f16ccdd544cbb7a84532 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x16841 | 400552 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.