Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 613bd0a3f2447710…

MALICIOUS

Office (OOXML) / .XLSX

717.9 KB Created: 2023-09-27 08:05:40 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2023-10-02
MD5: 6937a47fb1362267645b56f0511fbb3c SHA-1: a1c8b8cb081cf5b585cdf59a3bf12b4235a0ae4c SHA-256: 613bd0a3f2447710c8a65b23d029fd7ef1e2ac55581e1ae9282e2a13f8593dab
140 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The file contains an embedded OLE object, specifically identified as a vulnerable Equation Editor object. Heuristics indicate a NOP sled and an anomaly in the Ole10Native stream, suggesting it's designed to execute arbitrary code. The presence of these indicators strongly points to an exploit targeting the Equation Editor component.

Heuristics 4

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/0TOSnKVMc.7ShKn1U contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
819428b2870dbccaaf1bc2ece128dff3d5677eaa0e6182d0ef8f165810c7ac69
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/0TOSnKVMc.7ShKn1U 1001984 bytes
ooxml_oleobject_00_ole10native_00.bin
305e7a6a07934506f2b86ed057b373ce068f914ad2303d7f735ae42823f6807a
ole-package OOXML xl/embeddings/0TOSnKVMc.7ShKn1U Ole10Native stream: olE10NAtIvE 991427 bytes