Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9309d81abeb0a8e7…

MALICIOUS

Office (OOXML) / .XLSX

754.0 KB Created: 2021-04-28 14:40:56 UTC Authoring application: Microsoft Excel 15.0300
MD5: 7eaef19cc024f1c43914647e109c00c1 SHA-1: 7e1a1ff19263d373fcb57548ca272b746251c5ee SHA-256: 9309d81abeb0a8e779dcd9e63f6ec4ac8dc106b86b723adb42a0004af47b3e0a
82 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The high-severity heuristic firing for an Equation Editor OLE object indicates a likely exploit attempt. This type of embedded object is commonly used to deliver malicious payloads by leveraging vulnerabilities within the Equation Editor component. No further IOCs were extracted from this sample.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
bd3a67ff5ffb80df34bcb5068ac3b29b06a548805ac5289b2f0eeb41d0b5fb12
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 1035264 bytes