Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 1780af6c8c1a5e1b…

MALICIOUS

Office (OOXML) / .XLSX

755.2 KB Created: 2010-06-04 08:55:28 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2023-10-18
MD5: f1a23a4c5cd1eb390f13c9e23a86ee8f SHA-1: 4b7f309013b77e9d6410c31136a578b668f2e09d SHA-256: 1780af6c8c1a5e1b4758e82dc226f3c18c874ab4012c38fd9924a62bd2cc0d15
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The sample is an Office document containing an embedded OLE object, specifically identified as a Equation Editor object. High-severity heuristics indicate that this Equation Editor object carries a payload-like Ole10Native stream with an anomalous header and size discrepancy, strongly suggesting it's being used to deliver a secondary exploit or malware. The embedded OLE object is the primary indicator of malicious intent.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/xRRC7.QuMx contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
2e2b1c1b9feca5257af254bb3d82eb810ecb67f608654ce1ffef2c4530b91dc3
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/xRRC7.QuMx 1022976 bytes
ooxml_oleobject_00_ole10native_00.bin
3e47511d0d167c352881565c7102091e69c1b969a2f5bff855bd04500d0a62db
ole-package OOXML xl/embeddings/xRRC7.QuMx Ole10Native stream: oLE10nATIve 1012522 bytes