MALICIOUS
88
Risk Score
Malware Insights
MITRE ATT&CK
T1559.001 Component Object Model Hijacking
T1204.001 Malicious Link
T1059.005 Visual Basic
The presence of an Equation Editor OLE object and a GetPC stub strongly indicates exploitation of a known vulnerability within Microsoft Equation Editor. The VBA macros are present but appear to contain no executable statements, suggesting the primary malicious functionality is likely within the OLE object itself. The file's SHA256 hash is provided as a primary IOC.
Heuristics 3
-
Equation Editor OLE object high OLE_EQUATION_EDITORContains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.
-
x86 GetPC stub (CALL $+5; POP EBP) high SC_GETPC_CALLx86 GetPC stub (CALL $+5; POP EBP)
-
VBA project contains no executable statements low OLE_VBA_MACROSDocument contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 1206 bytes |
ole10native_00.bineed3fb91b963f5eec1634562424b5fe95dc3407ab18faf108e9aac469f552481 |
ole-package | OLE Ole10Native stream: MBD001FAE4D/Ole10NativE | 1849 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.