MALICIOUS
148
Risk Score
Malware Insights
MITRE ATT&CK
T1059 Command and Scripting Interpreter
T1204 User Execution
The file is an Excel spreadsheet with a high-confidence heuristic indicating an embedded Equation Editor object, a common vector for exploits. It also contains a secondary embedded PDF with suspicious static findings, suggesting it's designed to exploit PDF vulnerabilities. The presence of VBA macros, though not executable, further supports a malicious intent, likely to download and execute a second-stage payload.
Heuristics 5
-
Equation Editor OLE object high OLE_EQUATION_EDITORContains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.
-
Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGEA valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
-
x86 GetPC stub (CALL $+5; POP EAX) high SC_GETPC_CALLx86 GetPC stub (CALL $+5; POP EAX)
-
VBA project contains no executable statements low OLE_VBA_MACROSDocument contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ns.adobe.com/xap/1.0/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/g/img/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://ns.adobe.com/illustrator/1.0/
- http://ns.adobe.com/pdf/1.3/
Extracted artifacts 8
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 1206 bytes |
ole10native_00.bin90bb3d2932ec8d2ba59fb9f54bc19d5ef50229c3e586c4334e5fda840c7d99d7 |
ole-package | OLE Ole10Native stream: MBD012D310C/olE10nAtive | 1403 bytes |
stream_027_off0002ed5b.binb1d3870696b037464d54072ab0c6b02a60531ec979a87ca3c76ba3f09ac802ca |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x2ED5B | 457920 bytes |
icc_00_off00056af5.icc2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
pdf-icc-profile | PDF ICC profile at offset 0x56AF5 | 3144 bytes |
font_00_sfnt_off00057b87.bin8b9b49d3bcfcf773b551db446dd8c0b0b9077e2c0780475adbef04da72583906 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x57B87 | 1764 bytes |
polyglot_child_pdf_off00001000.pdf2bab56ade1479c017825c50e27a58f79f768a5aaac0f11e4897e59ad1829ea2c |
polyglot-child-pdf | Secondary PDF body inside ole container at offset 0x1000 | 972288 bytes |
polyglot_child_pdf_off00018a00.pdfd9bcdcce1c4e4d7f72b88b1251bdcbfc52952eef67ed2c290fe1127a95d20c93 |
polyglot-child-pdf | Secondary PDF body inside ole container at offset 0x18A00 | 875520 bytes |
polyglot_child_pdf_off00063200.pdf5640c1fa8a0b2d9ebdb5a2f9a9b7ded5f147d51d236429f68005342cc8e9f1bd |
polyglot-child-pdf | Secondary PDF body inside ole container at offset 0x63200 | 570368 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.