Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 4a662afebf865f33…

MALICIOUS

Office (OOXML) / .XLSX

763.1 KB Created: 2020-10-08 19:32:34 UTC Authoring application: Microsoft Excel 12.0000
MD5: 50b7771a6627a73b27c46273c0cbe425 SHA-1: 0f82ffb9a5224bb49714d6b16fc0674cc6a78926 SHA-256: 4a662afebf865f33884fee10b2068e5c287aeca6e100afaf06c154ca7f16fa1e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is an Excel spreadsheet containing an embedded OLE object, specifically identified as an Equation Editor object. The document body contains what appears to be a delivery order, suggesting a social engineering lure. The presence of the embedded OLE object is a strong indicator of malicious intent, likely to exploit vulnerabilities or deliver a secondary payload upon interaction.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/CWVJY1RQ.od contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
67c2d213f697ed786105143450ec91dfd4eee27996c8f8d1ce79e2e6f19c3723
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/CWVJY1RQ.od 971264 bytes
ooxml_oleobject_00_ole10native_00.bin
c26dad78ccd2d4b8e6655820acd1527386b00f5dd9baeb012b5a1a88569fd68c
ole-package OOXML xl/embeddings/CWVJY1RQ.od Ole10Native stream: OLE10naTive 961307 bytes