Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 412c5601b13b1dba…

MALICIOUS

Office (OOXML) / .XLSX

648.9 KB Created: 2024-03-25 10:30:17 UTC Authoring application: Microsoft Excel 12.0000
MD5: e842e1f4f53db4ea6d968b189c097ac6 SHA-1: 09de48c419408aa0515174ef4f9d2fcb0b058acc SHA-256: 412c5601b13b1dba89c0b491bc25ec4a670a667786da75a9390f8e689aa04e1c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The primary indicator of maliciousness is the presence of an embedded Equation Editor OLE object within the XLSX file. This object is frequently exploited to deliver malicious payloads by leveraging vulnerabilities in the Equation Editor component. No further scripts or document body content were extracted to provide additional context on the specific payload or delivery mechanism.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/x3.qeh contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
284df979b2dca189126cbc9bfd4e66fdcb455e603c4b47744e8a0fadc05715c9
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/x3.qeh 906752 bytes
ooxml_oleobject_00_ole10native_00.bin
d5daec7fc7c360852487fc2b4ab661112519d5e3591491fe826e5070192bae1b
ole-package OOXML xl/embeddings/x3.qeh Ole10Native stream: OLE10NATIVE 897501 bytes