Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b5b7cb8835bd6367…

MALICIOUS

Office (OOXML) / .XLSX

646.0 KB Created: 2010-06-04 08:55:28 UTC Authoring application: Microsoft Excel 15.0300
MD5: 871e7a177b52ac1b2f2ca384e76f74d5 SHA-1: 7787ca030d60567577ce9df9960af469ab57f562 SHA-256: b5b7cb8835bd6367de78615112669972ad36e0576b264827eca4c859eb1dcd54
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: Malicious Link T1559 Component Object Model Hijacking T1559.001 Component Object Model Hijacking: Component Object Model Hijacking

The sample is an OOXML document containing an embedded OLE object, specifically identified as a Microsoft Equation Editor object. This strongly suggests exploitation of a known vulnerability within the Equation Editor component. The embedded object, 'xl/embeddings/jG.xxy', is the likely vector for delivering a secondary payload. No scripts were extracted, and the document body contains what appears to be invoice-related text, which is likely a lure.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/jG.xxy contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
32a9675bcd44998a84f0bef201198631f9ced9498f0333afbadd3474c88b9590
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/jG.xxy 870912 bytes
ooxml_oleobject_00_ole10native_00.bin
cda66caa3cb7e631742711863976c0a572cdd50b46959c56baf78fed3603aab4
ole-package OOXML xl/embeddings/jG.xxy Ole10Native stream: olE10NAtIve 861546 bytes