MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1559.001 Component Object Model Hijacking
The high-severity heuristic firing for Equation Editor OLE object indicates the presence of a known exploit vector within the Excel file. This object is commonly used to exploit vulnerabilities, likely to download and execute a secondary payload. The embedded OLE object is the primary indicator of malicious intent.
Heuristics 2
-
Equation Editor OLE object high OLE_EQUATION_EDITOREmbedded OLE object xl/embeddings/1cCE0SYn.lXNVdN contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
-
Embedded OLE object medium OOXML_OLE_OBJECTDocument contains an embedded OLE object
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
ooxml_oleobject_00.bind87a19fc9c02f65dffd44cd8844911c0d19aa9547f58d6c3a270e8d324d00159 |
ooxml-ole-object | OOXML embedded OLE part: xl/embeddings/1cCE0SYn.lXNVdN | 2866688 bytes |
ooxml_oleobject_00_ole10native_00.bin8f4016801e561513c442600136afafff429f81dd745b0ce8647fc8da0e8cb926 |
ole-package | OOXML xl/embeddings/1cCE0SYn.lXNVdN Ole10Native stream: oLE10NATiVE | 2842068 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.