Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9f844efec47e875e…

MALICIOUS

Office (OOXML) / .XLSX

647.1 KB Created: 2023-08-03 11:34:29 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2024-08-17
MD5: b86cf1b4d3c0cf276c0440588358debc SHA-1: a1b22e67270f1e957c1e061a025da729e2f323be SHA-256: 9f844efec47e875ea3eaa387cae1de841dc48b283348fc36bc816fc77d0e00fb
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1559.001 Component Object Model Hijacking

The file contains an embedded OLE object, specifically identified as an Equation Editor object. This object exhibits an anomaly where the Ole10Native stream appears to carry a payload, indicated by an unusually large declared size compared to the actual stream size and a high entropy value. This strongly suggests the exploitation of a vulnerability within the Equation Editor to execute arbitrary code.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/I5momGaa.Yb4HTP contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
60e132b865b81bfb3b28054ebbbea3bb47805b78fac7f2dfdc6e5c2e57fda720
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/I5momGaa.Yb4HTP 921088 bytes
ooxml_oleobject_00_ole10native_00.bin
ed471d63cb3c7a2d94ccdfd774e8b33063465393d756c1bcbf1a60618eba8d87
ole-package OOXML xl/embeddings/I5momGaa.Yb4HTP Ole10Native stream: OLE10NaTIVE 911201 bytes