Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 b5182954de28b18b…

MALICIOUS

Office (OLE) / .XLS

953.5 KB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel
MD5: bbe2abbacb82f3f4f9fa3abca4fae1ed SHA-1: a3ab8be7ee9cc5b2932707aa1ba35e4f139d7ba8 SHA-256: b5182954de28b18b0490d4b88d1159dd074db8655ef9066d9274d75b408f8a74
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059 Command and Scripting Interpreter T1204 User Execution

The file is an Excel spreadsheet with a high-confidence heuristic indicating an embedded Equation Editor object, a common vector for exploits. It also contains a secondary embedded PDF with suspicious static findings, suggesting it's designed to exploit PDF vulnerabilities. The presence of VBA macros, though not executable, further supports a malicious intent, likely to download and execute a second-stage payload.

Heuristics 5

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Contains Equation Editor object — related to CVE-2017-11882 / CVE-2018-0802 exploitation, but CLSID presence alone is not the malformed MTEF exploit primitive.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • x86 GetPC stub (CALL $+5; POP EAX) high SC_GETPC_CALL
    x86 GetPC stub (CALL $+5; POP EAX)
  • VBA project contains no executable statements low OLE_VBA_MACROS
    Document contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/g/img/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/illustrator/1.0/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
7f506327609c082af1cd37dde23bc2c71a000f7d1ef530b6abb66775040a7673
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1206 bytes
ole10native_00.bin
90bb3d2932ec8d2ba59fb9f54bc19d5ef50229c3e586c4334e5fda840c7d99d7
ole-package OLE Ole10Native stream: MBD012D310C/olE10nAtive 1403 bytes
stream_027_off0002ed5b.bin
b1d3870696b037464d54072ab0c6b02a60531ec979a87ca3c76ba3f09ac802ca
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2ED5B 457920 bytes
icc_00_off00056af5.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x56AF5 3144 bytes
font_00_sfnt_off00057b87.bin
8b9b49d3bcfcf773b551db446dd8c0b0b9077e2c0780475adbef04da72583906
pdf-font-stream PDF embedded font (sfnt) at offset 0x57B87 1764 bytes
polyglot_child_pdf_off00001000.pdf
2bab56ade1479c017825c50e27a58f79f768a5aaac0f11e4897e59ad1829ea2c
polyglot-child-pdf Secondary PDF body inside ole container at offset 0x1000 972288 bytes
polyglot_child_pdf_off00018a00.pdf
d9bcdcce1c4e4d7f72b88b1251bdcbfc52952eef67ed2c290fe1127a95d20c93
polyglot-child-pdf Secondary PDF body inside ole container at offset 0x18A00 875520 bytes
polyglot_child_pdf_off00063200.pdf
5640c1fa8a0b2d9ebdb5a2f9a9b7ded5f147d51d236429f68005342cc8e9f1bd
polyglot-child-pdf Secondary PDF body inside ole container at offset 0x63200 570368 bytes