Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d0ff0a5fe47f75af…

MALICIOUS

Office (OOXML) / .XLSX

658.4 KB Created: 2023-08-28 00:33:21 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2023-08-28
MD5: c35c5ceca683d9173a9577559406c565 SHA-1: 2bbe5a651665eced6e8e960c7eb8ba647d5a88ab SHA-256: d0ff0a5fe47f75afadee4f2b22809ce9e5d8ee8983345e3da251ffe8f8edd920
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The sample is an OOXML file identified as malicious. High-severity heuristics indicate the presence of an embedded Equation Editor OLE object with an anomalous Ole10Native stream, suggesting it carries a malicious payload. The embedded OLE object and its associated Ole10Native stream are the primary indicators of compromise.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/hrTm.xN contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
9bb602f743425a89182e4f5b735771c78c978728467946a3ec07afd623109b66
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/hrTm.xN 901120 bytes
ooxml_oleobject_00_ole10native_00.bin
f3c18b4929b1fa25a9447834f7a51ef9d0d91045a69ef5fd745debd5b36e1f80
ole-package OOXML xl/embeddings/hrTm.xN Ole10Native stream: oLE10natIVe 891882 bytes