Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 c3cd06f1cd923b81…

MALICIOUS

Office (OLE) / .DOC

877.0 KB First seen: 2026-05-24
MD5: ecaf94586cc2e0d242891be40ed01a6a SHA-1: e8322c3166e52462c9009f725326ec4cfa972ced SHA-256: c3cd06f1cd923b81f43c690507d9bd1e36b62ea74941008daf4d16526ff0b8a9
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is a Microsoft Word document containing an embedded Equation Editor OLE object, which is a known vector for exploiting the Equation Editor vulnerability (CVE-2017-11882). This vulnerability allows for remote code execution when the document is opened. No document body text or scripts were extracted, but the presence of the vulnerable OLE object strongly suggests an exploitation attempt.

Heuristics 2

  • Equation Editor Ole10Native payload — CVE-2017-11882 critical CVE likely CVE_2017_11882_EQUATION_OLE10NATIVE
    An embedded Microsoft Equation 3.0 object (CLSID 0002CE02-0000-0000-C000-000000000046) carries an Ole10Native packager stream instead of the normal Equation Native/MTEF data. This is the weaponized Equation Editor RCE delivery shape used by CVE-2017-11882 / CVE-2018-0802 maldocs. The payload (font-record overflow + shellcode) is frequently encrypted and the stream name case-scrambled to evade scanners, but an Equation object holding an Ole10Native stream has no benign use.
  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Contains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ole10native_00.bin ole-package OLE Ole10Native stream: Ole10naTIvE 888545 bytes
SHA-256: c3bce1a062929ab551cf83546a703c71ac595958ea3e93f4f8b0b084a82ade50