MALICIOUS
70
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious File: User Execution
T1059.005 PowerShell
The critical heuristic firing for CVE-2017-0199 indicates the sample is designed to exploit this vulnerability. The embedded URL is used to fetch and execute a secondary payload, likely a malicious document or executable. The VBA macro source is present but contains no executable statements, suggesting the exploit is triggered by the OLE structure itself rather than macro code.
Heuristics 3
-
OLE2Link / URL Moniker → remote loader — CVE-2017-0199 critical CVE likely CVE_2017_0199Document contains an embedded OLE link object whose URL Moniker points to a remote URL. When the host file is opened, Office follows the link, downloads the URL, and processes the response based on its Content-Type (HTA -> mshta.exe, RTF → Word, etc.) — the documented CVE-2017-0199 primitive. The URL extension is not a reliable filter; servers can return different payloads to Office's user agent.
-
VBA project contains no executable statements low OLE_VBA_MACROSDocument contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://000000000000000000000000000000000000000000@185.246.220.166/_--00_o___o00_-oo-___---0-o_o0-__________o0o-__________/gggjjdfgjdfjghjfdggsahfhfghf.doc
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
macros.bas7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673 |
vba-macro | oletools.olevba.extract_macros (decoded VBA source) | 1206 bytes |
ole10native_00.bin18d367fb2691c250888963414e1f0f0f34a85093ea78ded4022d3b67fd43d3d2 |
ole-package | OLE Ole10Native stream: MBD01DC9A63/Ole10Native | 61938 bytes |
ole10native_01.bin0e74f03b42dbfb73650ae77db35efc03f254670fe5c220fbf54bacb45cb41486 |
ole-package | OLE Ole10Native stream: MBD01DC9A64/Ole10Native | 50530 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.