Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 aa856eccc097caa4…

MALICIOUS

Office (OOXML)

14.7 KB Created: 2011-03-22 06:52:17 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2019-11-20
MD5: 2f5abe07039b53c68c5be44f89c53aeb SHA-1: 68af62d47bae2f124af3f08f181956e9b05ae56d SHA-256: aa856eccc097caa460d6cbb10eda1ab476907d1d934ebf26f77462e26d806497
200 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is identified as malicious due to the presence of an embedded Equation Editor OLE object, which is a known exploit for CVE-2017-11882. The document body contains a lure instructing the user to 'CLICK ENABLE EDITING UP TO TRANSLATE LANGUAGE', indicating an attempt to bypass macro security and execute the exploit. The ClamAV detection further confirms the malicious nature, specifically flagging it as Doc.Exploit.CVE_2017_11882-6934206-0.

Heuristics 4

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Exploit.CVE_2017_11882-6934206-0
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 4608 bytes
SHA-256: b2bd9ffbcb4d1229881e5ae37f58890bbeb2f71b316d4d8bbd770b6c0fb77dfc
Detection
ClamAV: Doc.Exploit.CVE_2017_11882-6934206-0
Obfuscation or payload: unlikely