Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 49f179a825ab1316…

MALICIOUS

Office (OOXML) / .XLSX

2.20 MB Created: 2025-08-06 23:16:59 UTC Authoring application: Microsoft Excel 12.0000
MD5: ebc3658a808a3adf0a82cacfc821d4aa SHA-1: dff4300d2bd9d3b8a19db4ba2b2bb6027e68f0d9 SHA-256: 49f179a825ab131609af990ffdeb9c022d74dad8b0932624bfed26b10caac6ef
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The high-severity heuristic firing for an Equation Editor OLE object within an OOXML file indicates a strong likelihood of exploitation. This technique is commonly used to deliver malicious payloads by leveraging vulnerabilities in the Equation Editor component. No further IOCs were extracted from this sample.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/hKx.QPBBs contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
0076389e8db8fdc3bc227c37c64b6b593088a9b857e56e2c6fd5cdb686f6a50d
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/hKx.QPBBs 3057664 bytes