Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 06dad9e87ff647c4…

MALICIOUS

Office (OOXML) / .XLSX

734.4 KB Created: 2023-08-03 11:34:29 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2023-08-15
MD5: 19c6fca97c6525b85eebbdb7ef89de9e SHA-1: daa3f9dace30c705dd1eb476c38bab29f32752b1 SHA-256: 06dad9e87ff647c4b04e0fd371314b2a1c537c6ee2e6cad7ab6f4c15508e7c1f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1559.001 Component Object Model Hijacking

The file contains an embedded OLE object, specifically identified as a Equation Editor object. This object exhibits an anomaly where the Ole10Native stream appears to carry a payload, indicated by an impossible header and a significant size discrepancy. This strongly suggests the exploitation of a vulnerability within the Equation Editor to execute arbitrary code.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/ydR.X0Ta13u contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
b06afe112b089aefbe60f8ef6d82255bd2375fa5f2b75165cfc757424b38aa24
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/ydR.X0Ta13u 1011200 bytes
ooxml_oleobject_00_ole10native_00.bin
c04599f9323554b66b36c8877917055b0d7bec769be6122e8238719738dad7a6
ole-package OOXML xl/embeddings/ydR.X0Ta13u Ole10Native stream: oLE10NatIVe 1000807 bytes