Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6a94e8eaaa10d032…

MALICIOUS

Office (OOXML) / .XLSX

1.09 MB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 12.0000
MD5: 36a47ac43e18edc49e7433882c6b8b82 SHA-1: 91b13d548b329451bc72e6227c8ab7d6c34e25c5 SHA-256: 6a94e8eaaa10d0324ccb099fcaba42420078047bbb72195de2e6a94be9ec0706
62 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an Office Open XML spreadsheet containing an embedded OLE object, specifically identified as a Microsoft Equation Editor object. This type of object is known to be vulnerable to code execution exploits. The presence of the Equation Editor OLE object strongly suggests an attempt to leverage a known vulnerability for arbitrary code execution.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/z3y03GTTu.MHKWvtx contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
05adfce09ac6df72f8656da2d5bb8fd256f92ce5aea751478309984265a8e86b
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/z3y03GTTu.MHKWvtx 1378304 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.