Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 328375d8ca0983b2…

MALICIOUS

Office (OOXML) / .XLSX

745.6 KB Created: 2010-06-04 08:55:28 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2022-11-24
MD5: c98897abbf4121aad2673a2530ea54b1 SHA-1: 54c727dba9ed209df244eccecc88becea9f04711 SHA-256: 328375d8ca0983b2feca8d8b35d922b96736bab5894956355b85a41bd62a5223
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The file is an Office document containing an embedded OLE object, identified as an Equation Editor object. This technique is commonly used to exploit vulnerabilities in the Equation Editor component to execute arbitrary code. The embedded object is the primary indicator of malicious intent.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/xmn.l0 contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
bf0cad3c81170ab0652abd857322b27047dd69ff86b87e27685e73686cc00bf0
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/xmn.l0 1086464 bytes
ooxml_oleobject_00_ole10native_00.bin
46046f959fa110ae600352e3a2e3e38f586dd10b569dd549cae907e320f2a086
ole-package OOXML xl/embeddings/xmn.l0 Ole10Native stream: olE10NATive 1075537 bytes