Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 321a8b2a992d1d0d…

MALICIOUS

Office (OLE) / .XLS

1.13 MB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel First seen: 2026-03-09
MD5: 61549251372131156ff75d40d4b02020 SHA-1: 86cf701adf240df62715719548cee267eaaf1e23 SHA-256: 321a8b2a992d1d0dc5cfefb14b4b0e4ec75d73a3e0e4c21bce21b8a46d6f7401
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an Excel file containing an embedded Equation Editor OLE object. Heuristics indicate the presence of a payload exploiting CVE-2017-11882. This vulnerability allows for arbitrary code execution when the object is processed. No document body or scripts were extracted, but the presence of the vulnerable OLE object is sufficient evidence for exploitation.

Heuristics 2

  • Equation Editor Ole10Native payload — CVE-2017-11882 critical CVE likely CVE_2017_11882_EQUATION_OLE10NATIVE
    An embedded Microsoft Equation 3.0 object (CLSID 0002CE02-0000-0000-C000-000000000046) carries an Ole10Native packager stream instead of the normal Equation Native/MTEF data. This is the weaponized Equation Editor RCE delivery shape used by CVE-2017-11882 / CVE-2018-0802 maldocs. The payload (font-record overflow + shellcode) is frequently encrypted and the stream name case-scrambled to evade scanners, but an Equation object holding an Ole10Native stream has no benign use.
  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Contains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ole10native_00.bin
db73f191eca3e1845bf459ee9f333da4405fab4dcd6f8de33771818b2161bef4
ole-package OLE Ole10Native stream: MBD00024F41/Ole10NATIvE 1767 bytes