Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 523b1333440de7de…

MALICIOUS

Office (OLE) / .XLSX

625.5 KB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel First seen: 2023-06-05
MD5: a226551e5cbac16bb8eec9c87061130f SHA-1: f94762ca4943760551b4a9cfe9745c30482537aa SHA-256: 523b1333440de7de8a860d4c2fd687045d5338eb623847b730b6f2f1a26e3337
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The sample contains a critical heuristic firing for CVE-2017-0199, indicating it exploits a vulnerability in OLE2Link to load remote content. The embedded URL, http://45.66.230.217/windows/ikikikikikikikikikiki%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23ikikokikoikoikoi.doc, is likely the source of a second-stage payload. The document body appears to be malformed or truncated, providing no further context on the lure.

Heuristics 2

  • OLE2Link / URL Moniker → remote loader — CVE-2017-0199 critical CVE likely CVE_2017_0199
    Document contains an embedded OLE link object whose URL Moniker points to a remote URL. When the host file is opened, Office follows the link, downloads the URL, and processes the response based on its Content-Type (HTA -> mshta.exe, RTF → Word, etc.) — the documented CVE-2017-0199 primitive. The URL extension is not a reliable filter; servers can return different payloads to Office's user agent.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://45.66.230.217/windows/ikikikikikikikikikiki%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23ikikokikoikoikoi.doc