Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 069f290ac99a0ac6…

MALICIOUS

Office (OOXML)

2.55 MB Created: 2006-09-13 11:21:51 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2021-05-26
MD5: 350e72c49f2b5cdfb6e9fd36a9681b2c SHA-1: 26ac755b37f64a57703f2bba0a7ae8867cfbbab7 SHA-256: 069f290ac99a0ac6d118ba4f1edee0356bf86633e28c2f2b8cb512152bc0d346
108 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The sample is an OOXML document identified as malicious. It contains an embedded OLE object, specifically an Equation Editor object, which is flagged for carrying a payload-like Ole10Native stream. This suggests the object is designed to exploit vulnerabilities or deliver malware when opened. The document body contains invoice-like text, aligning with the SE_INVOICE_LURE heuristic.

Heuristics 4

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 853504 bytes
SHA-256: 5c43895f65c7e8fae17f2e822020dae18179cfcb6659eb5f81d8fb6addcf1d23
ooxml_oleobject_00_ole10native_00.bin ole-package OOXML xl/embeddings/oleObject1.bin Ole10Native stream: Ole10nAtIvE 844112 bytes
SHA-256: 293e44d8526b49e1c9410a506cc56a6c18eff2f2040243612dad52ca9b7aac5a