Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 de55457fddc34cf9…

MALICIOUS

Office (OOXML) / .XLSX

674.9 KB Created: 2024-03-25 10:30:17 UTC Authoring application: Microsoft Excel 12.0000
MD5: de3a722f1960ec377dc65801777473ec SHA-1: c7113ac323a42d610e5b74acbf957a417bcb4c7c SHA-256: de55457fddc34cf9a1a5b79aa0f68a57dfba122e8ee7faef6e2571cdd0cf36c7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The primary finding is a high-severity heuristic indicating an Equation Editor OLE object embedded within the XLSX file. This is a common technique used to deliver exploits, often targeting vulnerabilities within the Equation Editor component itself. The embedded OLE object is the most significant indicator of malicious intent.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/N4xL.a1Zd contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
cf6eb3fd6b066996ace9dfcf07a9224c55458b15f075e2ff9f6b18137739bca3
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/N4xL.a1Zd 968192 bytes
ooxml_oleobject_00_ole10native_00.bin
667c76a9bea3fa720c9d14c816581d82759c9794039ddd0bff549c25f86590a5
ole-package OOXML xl/embeddings/N4xL.a1Zd Ole10Native stream: oLe10NAtive 958118 bytes