Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 a26fa4d2169a2076…

MALICIOUS

Office (OOXML) / .XLSX

736.9 KB Created: 2010-06-04 08:55:28 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2023-04-21
MD5: 240da3fb4b1dfe2a7508c3d4ae401075 SHA-1: 5d0492dae681394fd28254da3ec09dba870cc45e SHA-256: a26fa4d2169a2076e5498feab397ac190dd3fdedf0d89802afecf8e1d833b342
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.001 Malicious Link

The file contains an embedded OLE object, specifically identified as a high-severity Equation Editor object with an anomalous Ole10Native stream. This indicates the exploitation of a known vulnerability within the Equation Editor component to embed and likely execute a malicious payload. The anomaly in the Ole10Native stream, with a declared inner size significantly larger than the stream size, strongly suggests an attempt to conceal or deliver an exploit. No document body text or scripts were extracted to provide further context on the specific lure or payload.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/vZX4.vMIC contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
f8a64a5de9c6411f1842bc8f27355e1b22d78ce6f6e6a704d8aa7f0a8facf1a8
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/vZX4.vMIC 1020416 bytes
ooxml_oleobject_00_ole10native_00.bin
2c851f2b73b6150f9fac03355192c8e6a313347afdeed1cb6f28e34919643e8f
ole-package OOXML xl/embeddings/vZX4.vMIC Ole10Native stream: olE10nATIve 1009939 bytes