MALICIOUS
110
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The sample is an Excel document containing an embedded Equation Editor OLE object, which is a known vector for exploiting vulnerabilities. The OLE object's Ole10Native stream exhibits anomalies suggesting it carries a payload. The document also contains an external hyperlink to 'http://www.astermedispro.com/', which may be related to the payload delivery or command and control.
Heuristics 5
-
Equation Editor OLE object high OLE_EQUATION_EDITOREmbedded OLE object xl/embeddings/eDwF.cP0CwC contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
-
Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALYEmbedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
-
Embedded OLE object medium OOXML_OLE_OBJECTDocument contains an embedded OLE object
-
External hyperlinks (2) low OOXML_EXTERNAL_HYPERLINKSDocument contains 2 external hyperlinks — clickable URLs are stored as external relationships. First target: http://www.astermedispro.com/
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.astermedispro.com/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
ooxml_oleobject_00.binb3c101519df952d46735983464f169614d3a49126d06fd678079c9ae73f86209 |
ooxml-ole-object | OOXML embedded OLE part: xl/embeddings/eDwF.cP0CwC | 1014784 bytes |
ooxml_oleobject_00_ole10native_00.binadb116afbb8178feca544dcd2023b06a1252f1ea0787b8747eabd69632be04a9 |
ole-package | OOXML xl/embeddings/eDwF.cP0CwC Ole10Native stream: OLE10natIVe | 1004463 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.