MALICIOUS
240
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious File
T1187 Exploitation for Client Execution
The file is identified as malicious by ClamAV with multiple critical detections, including 'Ppt.Malware.Laroux-10036124-0' and 'Xls.Trojan.Escape-1'. A critical heuristic firing indicates the presence of an OLE Package with an executable payload, specifically exploiting CVE-2014-4114. The presence of VBA macros, including an Auto_Open macro, further supports the malicious nature of the file, suggesting it's designed to execute arbitrary code upon opening.
Heuristics 5
-
CVE-2014-4114 — OLE Package with executable payload critical CVE likely CVE_2014_4114OLE Package CLSID found alongside executable file references — a strong CVE-2014-4114/Sandworm-style package-dropper indicator.
-
ClamAV: Ppt.Malware.Laroux-10036124-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Ppt.Malware.Laroux-10036124-0
-
ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAVClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
-
Auto_Open macro high OLE_VBA_AUTOAuto_Open macro
-
VBA macros detected medium OLE_VBA_MACROSDocument contains VBA macro code
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas541eb07333d24eadd909e9d021ed132dc31e8fdee58656d96463708977906aac |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 4140 bytes |
|
Detection
ClamAV:
Xls.Trojan.Escape-1
Obfuscation or payload:
unlikely
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.