Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 5cc9ded0f8036c49…

MALICIOUS

Office (OOXML) / .XLSX

620.2 KB Created: 2023-09-27 08:05:40 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2023-09-29
MD5: c6c1f5550ba032ce8cc907426b461b8f SHA-1: 8c7eda47bfa5d8480b47ab385a70bbd833f6a737 SHA-256: 5cc9ded0f8036c49d0b4f6af841953e7739429f1b8f7ff813b7db07abe287cf0
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The sample is an Office document containing an embedded OLE object identified as an Equation Editor. Heuristics indicate that this Equation Editor object carries a payload-like Ole10Native stream with an anomalous header, suggesting it's designed to exploit vulnerabilities or deliver malicious content. The presence of this embedded object is a strong indicator of a malicious document.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/n2.y9llkV contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
02343038bef5b41f9d3b5279784fd373fad19044a9cb17a7844e2e4b979edda0
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/n2.y9llkV 869888 bytes
ooxml_oleobject_00_ole10native_00.bin
f755d4e8f20cbac146d919c4d9936125389aab45a034c3c94ad4200ad21d4a68
ole-package OOXML xl/embeddings/n2.y9llkV Ole10Native stream: Ole10nATiVE 860283 bytes