MALICIOUS
88
Risk Score
Malware Insights
MITRE ATT&CK
T1204 Malicious Link
T1559.001 Component Object Model Hijacking
T1204.002 Malicious File
The presence of an Equation Editor OLE object strongly suggests exploitation of a known vulnerability within Microsoft Equation Editor. The 'x86 GetPC stub' heuristic further indicates code execution capabilities. Although no VBA macros were found to contain executable statements, the OLE object itself is the primary vector for exploitation. The file is identified as malicious with a high risk score.
Heuristics 3
-
Equation Editor OLE object high OLE_EQUATION_EDITORContains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.
-
x86 GetPC stub (CALL $+5; POP EDX) high SC_GETPC_CALLx86 GetPC stub (CALL $+5; POP EDX)
-
VBA project contains no executable statements low OLE_VBA_MACROSDocument contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 1206 bytes |
ole10native_00.bin1377662ad1d8fadf149a0b87b83999807dccddff3cca148479c6aeaa2d18bc5d |
ole-package | OLE Ole10Native stream: MBD0021BF4B/Ole10NaTiVe | 1878 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.