MALICIOUS
60
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
The file is an Excel document containing an embedded OLE object, specifically identified as an Equation Editor object. This strongly suggests exploitation of a known vulnerability within the Equation Editor component to achieve arbitrary code execution. No further details on payload or specific exploit chain were available from static analysis.
Heuristics 2
-
Equation Editor OLE object high OLE_EQUATION_EDITOREmbedded OLE object xl/embeddings/9v68n.lhl contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
-
Embedded OLE object medium OOXML_OLE_OBJECTDocument contains an embedded OLE object
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
ooxml_oleobject_00.bin65af45c662a6fd391496654351ff09141a2b6d1d3dfd84e50b4fcf0f06cd496d |
ooxml-ole-object | OOXML embedded OLE part: xl/embeddings/9v68n.lhl | 2970112 bytes |
ooxml_oleobject_00_ole10native_00.bin7774d2d82b87a810c35b5fe6360fc483fdb2bf6e549405083786c595758af88c |
ole-package | OOXML xl/embeddings/9v68n.lhl Ole10Native stream: oLe10nATIve | 2944119 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.