Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 d731386bf6a520af…

MALICIOUS

Office (OLE) / .XLSX

180.5 KB
MD5: 818056f61d211efc8b15f1d4fd3d294d SHA-1: a20888280d5be40c6db70e3391e120146d2d6c72 SHA-256: d731386bf6a520afec4e8a4031ea549ee2659f63af7652e9e9de66c11e24253a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The critical heuristic firing indicates exploitation of CVE-2017-0199 via a URL Moniker, which is used to download and execute a remote loader. The OOXML exploit carrier shape and default password encryption further support this finding. The embedded OLE object likely contains the malicious payload, and the extracted URL is the primary indicator of compromise for the remote resource.

Heuristics 3

  • OLE2Link / URL Moniker → remote loader — CVE-2017-0199 critical CVE likely CVE_2017_0199
    Document contains an embedded OLE link object whose URL Moniker points to a remote URL. When the host file is opened, Office follows the link, downloads the URL, and processes the response based on its Content-Type (HTA -> mshta.exe, RTF → Word, etc.) — the documented CVE-2017-0199 primitive. The URL extension is not a reliable filter; servers can return different payloads to Office's user agent.
    URL https://lillink.xyz/rFTfQ
  • Default-encrypted OOXML exploit carrier layout high OOXML_ENCRYPTED_EXPLOIT_CARRIER_SHAPE
    Default-password encrypted OOXML package contains embedded OLE object parts and additional activation/decoy parts. This layout is common in malicious Excel exploit delivery and requires inspecting the decrypted package.
  • Office OOXML encrypted with default VelvetSweatshop password medium OFFICE_DEFAULT_PASSWORD_ENCRYPTED_OOXML
    OLE EncryptedPackage decrypts with Excel's built-in VelvetSweatshop password. Office opens this transparently, and malware uses it to hide OOXML exploit parts from scanners that only inspect the outer OLE container.