Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 8d20fb8d41c862a2…

MALICIOUS

Office (OOXML)

17.3 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2019-01-11
MD5: c11dfc70bbb673fcc1225661e6fb4f27 SHA-1: 5655c1b3a2bac3eb3f0e2d95e7a95daf75a97979 SHA-256: 8d20fb8d41c862a28ba0f08bff0ab4fea82acf44c9f3ba9d2735029df5c61160
260 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is an Office document containing an embedded Equation Editor OLE object that exploits the CVE-2017-11882 vulnerability. This vulnerability allows for arbitrary code execution when the document is opened and the user is prompted to 'ENABLE EDITING'. The embedded OLE object is the primary indicator of malicious activity.

Heuristics 5

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Exploit.CVE_2017_11882-6934206-0
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 4096 bytes
SHA-256: b5e8bf601fdf286bc04b00809ac3e81433eade3b47c91d599a261952ca62a00c
Detection
ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0
Obfuscation or payload: unlikely