Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 8e4630490803b2a9…

MALICIOUS

Office (OLE) / .XLS

470.5 KB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel First seen: 2026-03-14
MD5: a3e71e6a68fa16583f75ab42bddcd598 SHA-1: e4188bd8f74a7697fb384a8b27e8e6d424e22089 SHA-256: 8e4630490803b2a94b44ccc85605eee1120274b7dc206d1b164d1a44484ce094
88 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.001 Malicious Link T1059.005 Visual Basic

The presence of an Equation Editor OLE object and a GetPC stub strongly indicates exploitation of a known vulnerability within Microsoft Equation Editor. The VBA macros are present but appear to contain no executable statements, suggesting the primary malicious functionality is likely within the OLE object itself. The file's SHA256 hash is provided as a primary IOC.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Contains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.
  • x86 GetPC stub (CALL $+5; POP EBP) high SC_GETPC_CALL
    x86 GetPC stub (CALL $+5; POP EBP)
  • VBA project contains no executable statements low OLE_VBA_MACROS
    Document contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1206 bytes
ole10native_00.bin
eed3fb91b963f5eec1634562424b5fe95dc3407ab18faf108e9aac469f552481
ole-package OLE Ole10Native stream: MBD001FAE4D/Ole10NativE 1849 bytes