Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 269801775bffc7e0…

MALICIOUS

Office (OOXML) / .XLSX

1.80 MB Created: 2022-11-21 03:38:49 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2023-01-25
MD5: e99a34703c132183790056d8c9c51be7 SHA-1: 1986f8aeb975e054dc64ae45aa753d51cd96976e SHA-256: 269801775bffc7e0a249e9accb7ae7c3e766d44e079e3366459a0df44e1b4b5f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1559 Component Object Model and Distributed Component Object Model T1559.001 Component Object Model

The primary finding is the presence of an embedded OLE object, identified as an Equation Editor object. This is a common technique used to exploit vulnerabilities or deliver secondary payloads. No specific scripts or document body content were extracted, limiting further analysis of the exact payload or delivery mechanism.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/57zbWC.G2R contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
8dc3924242ad0ad3aa83499bdac20947366a6c0d07daa57962e2d58e62fdf0d8
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/57zbWC.G2R 2214400 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.