MALICIOUS
304
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1140 Deobfuscate/Decode Files or Information
T1027 Obfuscated Files or Information
The sample is a Microsoft Office document that contains an embedded PE executable, identified by the 'OLE_EMBEDDED_EXE' heuristic. The 'OFFICE_PACKAGE_RISKY_FILE' and 'SE_PASSWORD_ARCHIVE_LURE' heuristics indicate that this embedded executable is likely intended to be delivered as a password-protected archive, a common tactic to evade initial security analysis. The presence of VirtualAlloc, LoadLibrary, and GetProcAddress API calls suggests the embedded executable is designed to load and execute code dynamically.
Heuristics 9
-
OLE with Ole10Native — possible CVE-2026-21514 exploitation high CVE likely CVE_2026_21514Document contains a Word OLE object with Ole10Native plus executable, PE, or risky remote-link indicators. CVE-2026-21514 exploits OLE metadata validation; this stronger structure is treated as likely exploitation.
-
Embedded PE executable critical OLE_EMBEDDED_EXEMZ/PE header found inside document — possible embedded executable
-
Ole10Native package drops an auto-executable payload critical OFFICE_PACKAGE_RISKY_FILEOLE Package displayName or fullPath ends in a directly auto-executable extension (a runnable binary or a script the default shell host runs on double-click). Embedding such a payload inside an Office document has no benign authoring use — it is a malware-delivery dropper.
-
Reference to LoadLibrary API high SC_STR_LOADLIBRARYReference to LoadLibrary API
-
Reference to GetProcAddress API high SC_STR_GETPROCADDRESSReference to GetProcAddress API
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOCReference to VirtualAlloc API
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://cisco.partnerelearning.com/Saba/Web/Main
- http://tftpd32.jounin.net
- https://kcteam.emea.eds.com/sites/1388/GNE-intern/Technics/documents/Internal_Training
- https://knowledgecentre.eds.com/sites/kc6/c3/Shared%20Documents/Export%20Compliance%20Position%20-%20Capability%20Documents.doc
- https://knowledgecentre.eds.com/Export
- http://gn.iweb.eds.com/software/
- http://www.cisco.com/en/US/products/ps6441/products_command_reference_chapter09186a00804ab444.html
- http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a00800a67f5.shtml
- http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080093f33.shtml
- http://www.heise.de/netze/lib/netzwerk-rechner.shtml
- http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/index.htm
- http://www.cisco.com/en/US/docs/routers/access/2600/hardware/installation/guide/2600ch1.html
- http://www.cisco.com/public/support/tac/tools.shtml
- https://knowledgecentre.eds.com/sites/kc6/default.aspx
- https://knowledgecentre.eds.com/sites/kc6/c3/Shared%20Documents/Network_Glossary.htm
- http://de.wikipedia.org/wiki/OSI-Modell
- http://de.wikipedia.org/wiki/Address_Resolution_Protocol
- http://de.wikipedia.org/wiki/Kollisionsdom%C3%A4ne
- http://de.wikipedia.org/wiki/Broadcast-Dom%C3%A4ne
- http://www.cisco.com/en/US/products/hw/switches/ps633/products_user_guide_chapter09186a008007efc8.html
- http://www.cisco.com/en/US/products/hw/routers/ps341/products_tech_note09186a00801a886f.shtml
- http://de.wikipedia.org/wiki/Crosskabel
- http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a00801f5d8f.shtml
- http://www.cisco.com/en/US/products/hw/routers/ps214/products_tech_note09186a00801f5d87.shtml
- http://www.cisco.com/en/US/products/hw/routers/ps274/products_tech_note09186a00800b0858.shtml
- http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_configuration_example09186a0080204528.shtml
- http://www.cisco.com/en/US/docs/ios/interface/command/reference/ir_c2.html
- http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00800b1500.shtml
- http://www.cisco.com/en/US/tech/tk389/tk621/technologies_tech_note09186a008009482f.shtml
- http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_dhcp_svr_cfg_ps9587_TSD_Products_Configuration_Guide_Chapter.html
- http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_dhcp_client_ps9587_TSD_Products_Configuration_Guide_Chapter.html
- http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_dhcp_rly_agt_ps9587_TSD_Products_Configuration_Guide_Chapter.html
- http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a008022493f.shtml
- http://www.cisco.com/en/US/tech/tk389/tk689/technologies_configuration_example09186a0080890607.shtml
- http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/5.x/configuration/guide/channel.html
- http://www.cisco.com/en/US/docs/switches/lan/catalyst2900xl_3500xl/release12.0_5_xp/eeswcfg/masctrnk.html
- http://standards.ieee.org/getieee802/download/802.1Q-2003.pdf
- http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/8.x/configuration/guide/sec_port.html
- http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_acl_ov_guideline_ps6350_TSD_Products_Configuration_Guide_Chapter.html
- http://www.cisco.com/en/US/tech/tk389/tk214/technologies_tech_note09186a0080094781.shtml
- http://www.cisco.com/en/US/docs/switches/lan/catalyst2950/hardware/installation/guide/hgovrev.html
- http://de.wikipedia.org/wiki/Medium_Dependent_Interface
- http://de.wikipedia.org/wiki/RS232
- http://cnx.org/content/m12293/latest/
- http://www.cisco.com/en/US/docs/ios/preface/usingios.html
- http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008010e9d5.shtml
- http://tools.ietf.org/html/rfc1918
- http://de.wikipedia.org/wiki/Private_IP-Adresse
- http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_tech_note09186a00800a6057.shtml
- http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080093f22.shtml
+33 more URL(s)
Extracted artifacts 21
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_office_0008989a.exe1e2c13ce12c130923aa4dd7c0c82fe53dfae209929c06a87cdcb752f2f37d2f9 |
embedded-pe | Office MZ+PE at offset 0x8989A | 1373030 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.62, consistent with packed or encrypted content.
|
|||
ole10native_00.bin5068fbdee33bafde7e84b7a6377c4197f12ba6f1510093a0fb26402443210070 |
ole-package | OLE Ole10Native stream: ObjectPool/_1235990337/Ole10Native | 1704 bytes |
ole10native_01.bin27a0b8f07b8a42fa51ded003c13e6f8aad8babeae6cd2321117979af6773e109 |
ole-package | OLE Ole10Native stream: ObjectPool/_1235992131/Ole10Native | 1077 bytes |
ole10native_02.binb7181ca9f626afee964926203e0648ba939f9c42b937b2e2c4441b5178979ccd |
ole-package | OLE Ole10Native stream: ObjectPool/_1236080524/Ole10Native | 1667 bytes |
ole10native_03.bind03f0ab8d06125ffce4b06aa4cf97e2054608c698d3d1f10191b9e1d8741e5d0 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236493050/Ole10Native | 1030 bytes |
ole10native_04.bin805f284f1b09f8cba7bf87b68813adf63fe014ab706e9d6bfa544fb82daa440b |
ole-package | OLE Ole10Native stream: ObjectPool/_1236493141/Ole10Native | 3107 bytes |
ole10native_05.bin3e7fd20fbc203e49390fbfbc30a98225aef2023c3372d69c00d16dfa516c8333 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236498606/Ole10Native | 2303 bytes |
ole10native_06.bin93f7cea4f04bce250e370adbdaf2921ffb9df0a2c94f27be45e0e8de4586e365 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236624316/Ole10Native | 1640 bytes |
ole10native_07.bin050c835318859635ec55b167ff03426bddb85da18f53cf9b0ec945ec95d8ef1c |
ole-package | OLE Ole10Native stream: ObjectPool/_1236664110/Ole10Native | 2361 bytes |
ole10native_08.bin63a85b7dcc7f8c43f41eed15cfec474f522bc8349048d243039c6567563d1d42 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236664332/Ole10Native | 3408 bytes |
ole10native_09.bina33261cca65ec5d4f331aff00ee2e193895963181e2ff35e45f5a32e8a45521c |
ole-package | OLE Ole10Native stream: ObjectPool/_1236664473/Ole10Native | 3959 bytes |
ole10native_10.bin7cb18cfa87cc1583ff92584b83808004e79dee28b8b9a52f5914c49018d88aa7 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236666283/Ole10Native | 2379 bytes |
ole10native_12.bin73a483898816d6edc6d2932dd70398803bffec63ce169f9478a35ccf1a1d2f96 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236666355/Ole10Native | 1403 bytes |
ole10native_13.bindca84607b37114a8a854a8535dc75a2631cbe6ce33f527df52aedfadf4de4425 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236666810/Ole10Native | 1851 bytes |
ole10native_14.bin2b31586902fb53743a048d0484f63faf934d7fd16828c91e926a17a005cdf33f |
ole-package | OLE Ole10Native stream: ObjectPool/_1236667962/Ole10Native | 1849 bytes |
ole10native_15.bin19f76fcff929990d44609d62b2918b7eaaf8351d4b28b85d14ec06d766710fa2 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236668186/Ole10Native | 1358 bytes |
ole10native_16.bin5bf736a4fd9c8e5369fe3a95e8e153e629b7a1a4bab51e9f31defbd987ec21cc |
ole-package | OLE Ole10Native stream: ObjectPool/_1236668550/Ole10Native | 1852 bytes |
ole10native_17.bine7a8f2ce8c5d717fa6a5b23ab9aed9a754ea3cc06fc661072f9ed423db5f6256 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236668899/Ole10Native | 1889 bytes |
ole10native_18.bina456ddbc2d7dab079084fa32b8ccc0c5daa82064bd6e7bc15248113355fadd61 |
ole-package | OLE Ole10Native stream: ObjectPool/_1236671275/Ole10Native | 2276 bytes |
ole10native_19.bind69c5ff96f4bd5168195ee178707d45cd32e7c92be467cb6cfe3104bd9a4967a |
ole-package | OLE Ole10Native stream: ObjectPool/_1236671276/Ole10Native | 2203 bytes |
ole10native_20.bin64d769b7fde991bdd62494a3d2b182bfdb38c1452721050e8f3bd46597df13d6 |
ole-package | OLE Ole10Native stream: ObjectPool/_1298959048/Ole10Native | 114844 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.