Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 36755efe28d33aa3…

MALICIOUS

Office (OLE) / .XLSX

1.15 MB
MD5: 228e1446d79bddd1bd2c560e4d7b5fe6 SHA-1: ac2231e30e73d8d21448726cccd3a91084555603 SHA-256: 36755efe28d33aa38c9dd517bc6c00a4cdd1e12045ba1719494a96037888be6b
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1071.001 Application Layer Compromise T1566.001 Privilege Escalation T1083 System Driver Update

The file utilizes a standard OOXML exploit delivery technique, embedding a malicious payload within a seemingly legitimate Excel file. The presence of the Equation Editor CLSID, combined with the unusual Ole10Native stream characteristics, strongly suggests an attempt to exploit CVE-2017-11882 or similar Equation Editor vulnerabilities. The decrypted package reveals further evidence of malicious intent, including the hidden exploit carrier and the potential for arbitrary code execution. The high heuristic scores further reinforce this assessment.

Heuristics 4

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Default-encrypted OOXML embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Default-encrypted OOXML exploit carrier layout high OOXML_ENCRYPTED_EXPLOIT_CARRIER_SHAPE
    Default-password encrypted OOXML package contains embedded OLE object parts and additional activation/decoy parts. This layout is common in malicious Excel exploit delivery and requires inspecting the decrypted package.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Default-encrypted OOXML embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is exploit-shaped Equation/OLE payload evidence.
  • Office OOXML encrypted with default VelvetSweatshop password medium OFFICE_DEFAULT_PASSWORD_ENCRYPTED_OOXML
    OLE EncryptedPackage decrypts with Excel's built-in VelvetSweatshop password. Office opens this transparently, and malware uses it to hide OOXML exploit parts from scanners that only inspect the outer OLE container.