Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 a2f57d0e79f8f06c…

MALICIOUS

Office (OOXML) / .XLSX

2.30 MB Created: 2025-09-04 00:14:20 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2025-09-04
MD5: 37bb173060bc1ef43f8b9e94f09a9676 SHA-1: e5ef8ba9032e2c28b977ea8290a7a60dea2d9fdd SHA-256: a2f57d0e79f8f06c984be2aac660569eedcb8fa3eff303bbe6baa42f6eeacd54
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The sample is an Office document containing an embedded OLE object, specifically identified as an Equation Editor object. Critical heuristic firings indicate the presence of the CVE-2017-11882 vulnerability, which is commonly exploited by attackers to execute arbitrary code. The document also contains a lure to enable macros, a typical method for bypassing security measures. The embedded OLE object is the primary indicator of compromise, likely serving as the initial vector for exploitation.

Heuristics 4

  • CVE-2017-11882 — Equation Editor FONT record overflow critical CVE likely CVE_2017_11882
    Equation Editor MTEF contains an overlong FONT typeface field, the vulnerable copy primitive for CVE-2017-11882. This is stronger evidence than the Equation Editor CLSID alone because it identifies the malformed record that drives code execution in EQNEDT32.EXE.
  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/fQVvb1n6.ukazC contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
279ec41cf90dd069260281086dd4c535620572bb11557df8ee3a90e858f39a04
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/fQVvb1n6.ukazC 3049984 bytes