Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 48f338c2d3c9e151…

MALICIOUS

Office (OOXML) / .XLSX

681.1 KB Created: 2010-06-04 08:55:28 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2023-08-24
MD5: 790d9448bce7140cdad662c5749abdd0 SHA-1: 1862ba8b6075d7373062fb40bd950144c9078423 SHA-256: 48f338c2d3c9e15165881f736b26b5e4e413890e1510bb002e2e83da68b01d88
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The sample is an Excel document containing an embedded OLE object, specifically identified as an Equation Editor object. Heuristics indicate that this Equation Editor object carries a payload-like Ole10Native stream with an anomalous size and header, strongly suggesting exploitation of a vulnerability within the Equation Editor. This technique is commonly used to download and execute a second-stage payload.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/ToPhp.EiaU contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
9dc23023f4bde21b4f3e98c7397d46a8643f41277169dbf73f577a8b8c36d896
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/ToPhp.EiaU 932352 bytes
ooxml_oleobject_00_ole10native_00.bin
f11966d96e666738eba060caf4c5c0d65c6ab53f75d473add286e7b830cee827
ole-package OOXML xl/embeddings/ToPhp.EiaU Ole10Native stream: olE10nAtivE 922210 bytes