MALICIOUS
88
Risk Score
Malware Insights
MITRE ATT&CK
T1559.001 Component Object Model Hijacking
T1204.002 Malicious File
The presence of an OLE object associated with Equation Editor (OLE_EQUATION_EDITOR) strongly suggests exploitation of a known vulnerability within this component. The GetPC stub firing further indicates code execution capabilities. Although VBA macros were detected, they contained no executable statements, implying the exploit is likely embedded directly within the OLE object itself rather than being triggered by macro code. No specific malware family could be identified.
Heuristics 3
-
Equation Editor OLE object high OLE_EQUATION_EDITORContains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.
-
x86 GetPC stub (CALL $+5; POP EBX) high SC_GETPC_CALLx86 GetPC stub (CALL $+5; POP EBX)
-
VBA project contains no executable statements low OLE_VBA_MACROSDocument contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 1206 bytes |
ole10native_00.bina1d5e2188fcac06d1b7ab2905499c139ef98ee54f986b00687198bd884fed9ae |
ole-package | OLE Ole10Native stream: MBD012F994D/oLE10NATIVe | 1568 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.