Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 58e63f3ba7fe0b25…

MALICIOUS

Office (OOXML) / .XLSX

2.06 MB Created: 2025-06-12 01:12:31 UTC Authoring application: Microsoft Excel 12.0000
MD5: 849065bcbaf5a18007d410eb537efe70 SHA-1: 0c6212149940b9fcdbcc186febe7860035c7b7fa SHA-256: 58e63f3ba7fe0b25fbaa18ee9ec990bd9786570e84a10e34cdbe357e94893e6f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The file is an OOXML document containing an embedded OLE object, specifically identified as a Microsoft Equation Editor object. This object is known to be a vector for exploiting vulnerabilities like CVE-2017-11882, which allows for arbitrary code execution. The presence of a NOP sled further supports the likelihood of shellcode execution within the embedded object. The primary attack vector appears to be the exploitation of the Equation Editor to achieve code execution, likely for downloading and executing a subsequent stage.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/yVViZwkT.u7tU contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
bb8e61f51e4d0f6dd9966df9d13b87f395756bfa53c2db4d26bae94a6a28e0ce
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/yVViZwkT.u7tU 2937856 bytes
ooxml_oleobject_00_ole10native_00.bin
9d54968bc81cc09effde9924d91b3f807147e1630ecbfa7296de66df9697f705
ole-package OOXML xl/embeddings/yVViZwkT.u7tU Ole10Native stream: oLe10nAtive 2912320 bytes