Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 406a9de8f5641a60…

MALICIOUS

Office (OLE) / .XLSX

410.3 KB
MD5: 62a8508629f28f3f7c17c296097374b8 SHA-1: ff632f100b6bdcd06195b25e3e8ad5e4949c71d2 SHA-256: 406a9de8f5641a60a4f6891e4371e05aa6fbbec85ba4cc0cecb14ec22c1b7571
180 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file is an encrypted Excel spreadsheet that contains an embedded OLE object, specifically identified as an Equation Editor object. This combination of heuristics strongly suggests it's an exploit carrier. The encryption and malformed structure indicate an attempt to obscure malicious content, likely leveraging a known Equation Editor vulnerability to execute arbitrary code. No document body or scripts were extracted, but the presence of the Equation Editor OLE object is a critical indicator of exploit delivery.

Heuristics 5

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Default-encrypted OOXML embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Encrypted Office package with CFB FAT corruption critical OLE_ENCRYPTED_AND_MALFORMED
    Encrypted-package shape co-occurs with FAT-chain corruption — the documented combined evasion form.
  • Default-encrypted OOXML exploit carrier layout high OOXML_ENCRYPTED_EXPLOIT_CARRIER_SHAPE
    Default-password encrypted OOXML package contains embedded OLE object parts and additional activation/decoy parts. This layout is common in malicious Excel exploit delivery and requires inspecting the decrypted package.
  • Office document is password-encrypted medium OFFICE_ENCRYPTED_PACKAGE
    OLE container holds MS-OFFCRYPTO encrypted package (Standard Encryption (Office 2007, AES)).
  • Office OOXML encrypted with default VelvetSweatshop password medium OFFICE_DEFAULT_PASSWORD_ENCRYPTED_OOXML
    OLE EncryptedPackage decrypts with Excel's built-in VelvetSweatshop password. Office opens this transparently, and malware uses it to hide OOXML exploit parts from scanners that only inspect the outer OLE container.