Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 941e0547c51948f5…

MALICIOUS

Office (OLE) / .XLS

197.0 KB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel First seen: 2022-11-02
MD5: 8929528f1020108fb8b259a3e348f322 SHA-1: b2d3999e307b587c876301cdc63e9e660d897cb2 SHA-256: 941e0547c51948f5a4e8798b2455eb420d48923f042a4fd8bfadef2956dca6cd
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The critical heuristic firing for CVE_2017_11882_EQUATION_OLE10NATIVE strongly indicates exploitation of this known vulnerability. The presence of an Equation Editor OLE object further supports this finding. The embedded OLE package likely contains the secondary payload, though its exact nature cannot be determined from the provided evidence.

Heuristics 2

  • Equation Editor Ole10Native payload — CVE-2017-11882 critical CVE likely CVE_2017_11882_EQUATION_OLE10NATIVE
    An embedded Microsoft Equation 3.0 object (CLSID 0002CE02-0000-0000-C000-000000000046) carries an Ole10Native packager stream instead of the normal Equation Native/MTEF data. This is the weaponized Equation Editor RCE delivery shape used by CVE-2017-11882 / CVE-2018-0802 maldocs. The payload (font-record overflow + shellcode) is frequently encrypted and the stream name case-scrambled to evade scanners, but an Equation object holding an Ole10Native stream has no benign use.
  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Contains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ole10native_00.bin
cb2e83a256230e85af1dd7cf90b14191060b5d80637ca797609759e1abef79d0
ole-package OLE Ole10Native stream: MBD03FA1F4C/OLE10naTIve 1733 bytes