Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 480886e5da8b8a5e…

MALICIOUS

Office (OOXML) / .XLSX

742.1 KB Created: 2023-11-17 18:26:59 UTC Authoring application: Microsoft Excel 12.0000
MD5: 4368cca1c8547e47e29afcd9f0a0e3ba SHA-1: a24a70df654508656ef9f22fd44f1bb5f1fe82fb SHA-256: 480886e5da8b8a5e91ea8c780db6cc9e427b5eaf6a585d5897b68aaba6a10dee
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The sample is an Excel file containing an embedded OLE object, specifically identified as an Equation Editor object. This strongly suggests exploitation of a known vulnerability within the Equation Editor component to execute arbitrary code. The embedded OLE object itself is a primary indicator of compromise.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/cq.DC contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
5e9124fc8c502fa7818268584bbc7501e2991c39cdf88cabde3a3bbb4e93eb34
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/cq.DC 1082368 bytes
ooxml_oleobject_00_ole10native_00.bin
a95e7adcf834595e1d2cd550061bf1c0f5cb70e2916be7d555c2954fb5ee7a40
ole-package OOXML xl/embeddings/cq.DC Ole10Native stream: OlE10NAtivE 1071369 bytes