Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9a4a1efcc0eebc51…

MALICIOUS

Office (OOXML) / .XLSX

593.3 KB Created: 2022-08-10 18:51:50 UTC Authoring application: Microsoft Excel 16.0300
MD5: b4e3ff7981753c7ec1eabcdc016c20f8 SHA-1: 91966ad4733711f0a94fc8009a563aa1922ebc45 SHA-256: 9a4a1efcc0eebc5159f2f14d936e870d82d5eec9abcf53fbe3d1e6f432ef730a
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1559.001 Component Object Model Hijacking

The file is an Office document containing an embedded OLE object, specifically identified as an Equation Editor object. Heuristics indicate the presence of a NOP sled and an Equation Editor OLE object, strongly suggesting exploitation of a known vulnerability (CVE-2017-11882) within the Equation Editor component. The embedded OLE object is the likely vector for delivering a secondary payload.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/ZXVgpWahM.y9I0s36 contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
3e7d104d60d811317a261cc2bea68c26f8ac6736bd5e6f484605c8722db97d8d
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/ZXVgpWahM.y9I0s36 840192 bytes
ooxml_oleobject_00_ole10native_00.bin
79154929be48033ebf3c4fe7a536c07d372c06ee5430db044f6cf5bc71f26fbc
ole-package OOXML xl/embeddings/ZXVgpWahM.y9I0s36 Ole10Native stream: OlE10NaTiVe 831211 bytes