Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 989421491c9d7600…

MALICIOUS

Office (OOXML) / .XLSX

581.7 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 12.0000
MD5: fa8aa543ac62efd559594d0e40f14633 SHA-1: 3c5126e9187b9595ae0662fb7f4f0ac4bfd56663 SHA-256: 989421491c9d76007dc70558f04aa8fa4b58d0827e1bf776b35f00e7de74044a
110 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file is an Excel document containing an embedded OLE object, specifically identified as an Equation Editor object. High-severity heuristics indicate the presence of CVE-2018-0798, an anomaly within the Equation Editor's native stream, strongly suggesting exploitation for arbitrary code execution. No VBA or scripts were extracted, but the OLE object itself is the primary attack vector.

Heuristics 5

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • CVE-2018-0798 — anomalous Equation Editor native stream high CVE likely CVE_2018_0798_EQUATION_NATIVE_ANOMALY
    Embedded Equation Editor OLE data contains anomalous native stream bytes consistent with a CVE-2018-0798-style Equation Editor exploit. This is treated as likely CVE evidence because the Equation object is malformed and payload-like, but it does not match the exact public matrix-overflow byte signature.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Hidden worksheet (hidden) low OOXML_HIDDEN_SHEET
    Excel workbook contains 1 hidden sheet(s) — hidden sheets are commonly used to conceal macro code, staging data, or intermediate payload construction
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.day.com/dam/1.0
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/tiff/1.0/
    • http://purl.org/dc/elements/1.1/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
701f358b7ad4eaea333f07d5788b67603365673ab5b5448a8e950df4ffa64e02
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 4096 bytes
ooxml_oleobject_00_ole10native_00.bin
a1686c930f44d03cebb423b84f3a2929cc858cbb79302e4d70338cbadc1330ea
ole-package OOXML xl/embeddings/oleObject1.bin Ole10Native stream: Ole10native 1834 bytes
ooxml_oleobject_01.bin
45564df67d2d280db72017c865e85d4713dafb05448061e2338f73a2b406c1c5
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject2.bin 11776 bytes
ooxml_oleobject_01_ole10native_00.bin
2065a5e0f7398e87f76c05191fd323df059d099ddbb52bd9c3666a365e3efdce
ole-package OOXML xl/embeddings/oleObject2.bin Ole10Native stream: Ole10Native 9788 bytes
emf_00.emf
740740a2241b7fcb00d1738f2b86dd2650a43134791979a2e52c93364cc9d18b
ooxml-emf OOXML EMF part: xl/media/image9.emf 648132 bytes
emf_01.emf
b8956184e4e7c8673f94d590d61b3d02ac7b6ac5634b8c063f220361c7da2567
ooxml-emf OOXML EMF part: xl/media/image10.emf 7788 bytes