Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 ea00a39d27021c79…

MALICIOUS

Office (OOXML) / .XLSX

741.8 KB Created: 2023-07-26 19:45:53 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2023-09-20
MD5: 005e8c25629dcc12b108fe095cc1cc53 SHA-1: aa6d942c45ba7201b4c5dd3cde5e636a91ab7535 SHA-256: ea00a39d27021c79cf23c4af361a98707ca96f93f0743e51a0f7910c579eace9
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file contains an embedded OLE object, specifically identified as a Equation Editor object with an anomalous Ole10Native stream. This strongly suggests exploitation of a known vulnerability within the Equation Editor component to execute arbitrary code. The presence of this object is the primary indicator of malicious intent, likely leading to the download and execution of a secondary payload.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/DA.nwjW contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Equation Editor object carries payload-like Ole10Native stream high OLE_EQUATION_OLE10NATIVE_PAYLOAD_ANOMALY
    Embedded OLE object declares the Equation Editor CLSID but stores a large high-entropy Ole10Native stream with malformed package sizing. This is an exploit-shaped Equation/OLE payload container seen in malicious OOXML samples. It is not assigned to a specific CVE unless the MTEF/Equation Native primitive also matches.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
61e7e4f6900de5afd160fff205e294cad3f04cd1c9dbcad53fc48477f55484f2
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/DA.nwjW 1065984 bytes
ooxml_oleobject_00_ole10native_00.bin
fec7189d8ecf1dc93206360bb497dfcb983dacb32af4bf7d5a368ab38b290512
ole-package OOXML xl/embeddings/DA.nwjW Ole10Native stream: olE10NAtIVe 1055064 bytes