Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6fe2206f0f078cd9…

MALICIOUS

Office (OOXML) / .XLSX

733.8 KB Created: 2022-08-10 18:51:50 UTC Authoring application: Microsoft Excel 16.0300
MD5: 50ba3b12df9a95cbf498022673e4fbe9 SHA-1: 7a5870beeed1a009e612ddcf481efad5792af493 SHA-256: 6fe2206f0f078cd9bb9451d636752e1207ff7d57f5c75747b481a0efa1270755
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file is an Excel document containing an embedded OLE object, specifically identified as an Equation Editor object. Heuristics indicate that this Equation Editor object contains a payload-like Ole10Native stream with an anomalous header, suggesting it's being used to exploit a vulnerability. This is a known technique for delivering malicious payloads via crafted documents.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/nmI5.Lo2S contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
c5e04c2a593d997984be623aa0d60e613b9908622adf56a44ce31ab8bc141118
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/nmI5.Lo2S 1063424 bytes
ooxml_oleobject_00_ole10native_00.bin
baa14e4849f306716bc9bcdde7e8b62ec1c18bc08de28c2e37dc28a50530e6a0
ole-package OOXML xl/embeddings/nmI5.Lo2S Ole10Native stream: olE10naTIVe 1052450 bytes