Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e93c18ec424bb9d3…

MALICIOUS

Office (OOXML) / .XLSX

2.43 MB Created: 2025-10-29 06:20:05 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2025-11-20
MD5: 4659b6d1f311ab20549fd7c010464e67 SHA-1: ba5de2aa9c34216eba06b0b149dc0e9730c404f1 SHA-256: e93c18ec424bb9d34fa8e515d92b8341f77c30b068654be61018aa53a9ab2e6c
100 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model and Distributed Component Object Model T1204.002 Malicious File

The file is an Excel spreadsheet containing an embedded OLE object, specifically identified as a Microsoft Equation Editor object. Heuristics indicate that this Equation Editor object carries a payload-like Ole10Native stream with an anomalous header, suggesting it's being used to deliver a secondary exploit or payload. The document body content appears to be unrelated Wikipedia text, indicating it's likely a lure.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/t1ndZdF.0kqAKhR contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
81a9e5a256c67e04040cd2502bdfe4d4fb46248e326201b0f3f39de98c48ef11
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/t1ndZdF.0kqAKhR 2970112 bytes
ooxml_oleobject_00_ole10native_00.bin
4be63ba426a607670e99eee804794007ee48052b0bdac0f329e80b43bfc0795c
ole-package OOXML xl/embeddings/t1ndZdF.0kqAKhR Ole10Native stream: OLE10NaTivE 2944333 bytes