Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 df1338e7062eed6e…

MALICIOUS

Office (OOXML) / .XLSX

592.3 KB Created: 2023-08-03 11:34:29 UTC Authoring application: Microsoft Excel 16.0300
MD5: 93b19b29033274f67bf71328afd3d0ed SHA-1: 2c805abf9d51d9cd6938faef7d0c4202c2e0e98f SHA-256: df1338e7062eed6e189216fe0791fed4c89c32373982a854ccd4af7201352d6b
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an Excel file containing an embedded OLE object, specifically identified as an Equation Editor object. Heuristics indicate this object is anomalous and exploits CVE-2018-0798, a vulnerability in Microsoft Equation Editor that allows for arbitrary code execution. This suggests the file is designed to deliver a malicious payload via the Equation Editor exploit.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/hpMSl0xX.as43Lt contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • CVE-2018-0798 — anomalous Equation Editor native stream high CVE likely CVE_2018_0798_EQUATION_NATIVE_ANOMALY
    Embedded Equation Editor OLE data contains anomalous native stream bytes consistent with a CVE-2018-0798-style Equation Editor exploit. This is treated as likely CVE evidence because the Equation object is malformed and payload-like, but it does not match the exact public matrix-overflow byte signature.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
300e63703eecac8a28defb5f05182251ce1b94117f00dcefa1c91e889623b01e
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/hpMSl0xX.as43Lt 800768 bytes
ooxml_oleobject_00_ole10native_00.bin
40bc1ae125963acb91d08f95ec3a8f36d65b7e398a3d228b014ba33cc8729520
ole-package OOXML xl/embeddings/hpMSl0xX.as43Lt Ole10Native stream: Ole10nAtIVe 792004 bytes