Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 97b5c0670c7738b1…

MALICIOUS

Office (OOXML)

9.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2019-09-30
MD5: 6a84f3e188d983b39efc64766bcdaac2 SHA-1: 3502581f246925bdea3e7f53f9cb64cef1ff1b4b SHA-256: 97b5c0670c7738b1624f71fd0213d373d35a17506e7aaf5e3087a0b33e6dc3bf
240 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The critical heuristics indicate the presence of the CVE-2017-11882 vulnerability within an embedded Equation Editor OLE object. This exploit is known to allow for arbitrary code execution. The file is classified as malicious due to this critical vulnerability.

Heuristics 4

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Exploit.CVE_2017_11882-6934206-0
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 3584 bytes
SHA-256: de866c3281f1beb981e28298d2839c13e404d3e802993253ce454baa566dcd86
Detection
ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0
Obfuscation or payload: unlikely