Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e25acc343e112b56…

MALICIOUS

Office (OOXML) / .XLSX

1.54 MB Created: 2021-09-22 12:07:42 UTC Authoring application: Microsoft Excel 12.0000
MD5: 3f92948ed6eb89af2861d6613ad26a43 SHA-1: 5a5f1a0754f2105e91109ed9c0699db8410d9c44 SHA-256: e25acc343e112b56ab0e2b955e538d792fa6dc04437c22460fbf0a8be72328bf
62 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The primary indicator of maliciousness is the presence of an embedded OLE object identified as an Equation Editor. This is a common technique used to exploit vulnerabilities in Microsoft Office applications, often leading to the execution of arbitrary code. No document body or scripts were extracted, limiting further analysis of the specific payload or delivery mechanism.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/nXfw4xw.iB4 contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
c20e047eb9003f69ff71897b83f0bbcc498a9b1a204d6c6e6e660b9ed845480c
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/nXfw4xw.iB4 1951744 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.