Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6c6cb8625f36ebd0…

MALICIOUS

Office (OOXML) / .XLSX

699.6 KB Created: 2023-11-17 18:26:59 UTC Authoring application: Microsoft Excel 12.0000
MD5: cf84d69f2cf41f746410ac7731e7469b SHA-1: 4164ec85fdf0db6ba00ec567616c65defcfba8b7 SHA-256: 6c6cb8625f36ebd02fe3ef1e5647b8b1f625500795b582cd3d21dacadb00daa2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The file is an Excel spreadsheet that contains an embedded OLE object, specifically identified as an Equation Editor object. This type of object is frequently exploited to execute arbitrary code. The document body presents itself as a financial calculation, likely a lure to encourage the user to interact with the malicious content. The presence of the Equation Editor OLE object strongly suggests an attempt at exploitation for client execution.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/eXmo7xQ.cx6drbM contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
bedc777976d7a50c955c377b9f1db79c47359681110ee090b729e89acc5f942e
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/eXmo7xQ.cx6drbM 988672 bytes
ooxml_oleobject_00_ole10native_00.bin
990237651a1fe79037965d6e8ab5858700bdaf2deba97ecaf88134d2127a2d56
ole-package OOXML xl/embeddings/eXmo7xQ.cx6drbM Ole10Native stream: OLe10nAtiVe 978297 bytes