Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e89a7160d5efc1e3…

MALICIOUS

Office (OOXML) / .XLSX

2.20 MB Created: 2025-08-18 05:08:49 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2025-08-22
MD5: 75e418cb5311d0b811dd0f2688881f80 SHA-1: 76215f563274d6235b5bc63a941deb62f3403ad1 SHA-256: e89a7160d5efc1e36b5ffb45c17c1b08c6126ee9b66e336e08acdfd48eb5aaea
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The file is an Excel document containing an embedded OLE object, identified as an Equation Editor. Heuristics indicate that this Equation Editor object carries a payload-like Ole10Native stream with an anomalous structure, strongly suggesting exploitation of CVE-2017-11882 or a similar vulnerability. The document body content appears to be garbled or non-standard, providing no clear user-facing lure.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/ur8.LIsEW contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
e61a579cb0520108055e987dd4224af38e65949804f70eed7f1d8303a40ddf6a
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/ur8.LIsEW 3041792 bytes
ooxml_oleobject_00_ole10native_00.bin
4b9e2fec44f87c722b94156d85ae471900c6609dccf406f07e172fa174361245
ole-package OOXML xl/embeddings/ur8.LIsEW Ole10Native stream: OLE10NATIve 3015611 bytes