Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 3bf120c035608cd4…

MALICIOUS

Office (OOXML) / .XLSX

2.80 MB Created: 2025-09-10 01:57:00 UTC Authoring application: Microsoft Excel 15.0300
MD5: 10da8fca0693ea66ceebbd673240f15d SHA-1: 3d5c0573c241eb9970fe411bcf24b9537c76732e SHA-256: 3bf120c035608cd4d738ce422a8ec07b35147b9b7c3b031888adf3769ead23af
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The high-severity heuristic firing for 'Equation Editor OLE object' indicates the presence of a known exploit vector within the embedded OLE object. This technique is commonly used to execute arbitrary code by exploiting vulnerabilities in the Equation Editor component. The embedded OLE object itself is the primary indicator of compromise.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/a2Vp4MTNH.iPHVEx contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
3f30645544729b5265fd0d0b1c0133f9f756d8550134b922b215e227027a82a3
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/a2Vp4MTNH.iPHVEx 2848768 bytes
ooxml_oleobject_00_ole10native_00.bin
0b6fd33cc9bdcf76fe038eed3f78acbc58ee36b9408905dcc09a618a32dc4993
ole-package OOXML xl/embeddings/a2Vp4MTNH.iPHVEx Ole10Native stream: olE10nATIVE 2824076 bytes