Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e418ac2813daadef…

MALICIOUS

Office (OOXML) / .XLSX

601.8 KB Created: 2023-08-03 11:34:29 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2023-10-11
MD5: fd3dec0db12c7f695e5a25e21acb7092 SHA-1: 8b17ef60cae44a17a2b91e3386b47420d5a41d04 SHA-256: e418ac2813daadef8ed238148ab1b1037567e126271316157d7955b2ce6fa858
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The sample is an Office Open XML spreadsheet containing an embedded OLE object, specifically identified as an Equation Editor object. This object is known to be used to exploit vulnerabilities, such as CVE-2017-11882, to execute arbitrary code. The presence of a NOP sled further indicates shellcode execution.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/5cBgUFuq.GA contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
46019d0e8d8b3d87a5a5d9d2fbcc4a41be4f389378f0c01a67b705da9886635b
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/5cBgUFuq.GA 860672 bytes
ooxml_oleobject_00_ole10native_00.bin
1607b0e3965d99eff68d427ff76832214c5982ffb3ee2f5f91b7499b7d904026
ole-package OOXML xl/embeddings/5cBgUFuq.GA Ole10Native stream: OlE10nAtIve 850982 bytes