Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 eb4e70d8e0a67074…

MALICIOUS

Office (OOXML) / .XLSX

718.3 KB Created: 2022-08-10 18:51:50 UTC Authoring application: Microsoft Excel 16.0300
MD5: ebacb7db12e14d8dbebf382780034c2b SHA-1: c514dc839fe03aabd2c21ab299220f00d03e8c13 SHA-256: eb4e70d8e0a67074bf67287ee7698f1279c41d8e265964e0aad2ebe938db5222
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: Malicious Link T1559 Component Object Model Hijacking T1559.001 Component Object Model Hijacking: Component Object Model Hijacking

The file is an Excel document containing an embedded OLE object, specifically identified as a Microsoft Equation Editor object. This type of object is known to be exploited to deliver malicious payloads. The presence of the Equation Editor OLE object strongly suggests an attempt to leverage a known vulnerability for code execution, likely leading to the download and execution of a secondary payload.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/tEkI.qQoFO3 contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
151691ced8f26d9021024dca9287306fa3ccdb43e0ed3c334b10ff74a366aed2
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/tEkI.qQoFO3 1019904 bytes
ooxml_oleobject_00_ole10native_00.bin
0dbaeea16799c9577134a59feaee9932210f16f804ce326d936cb99210dc91fb
ole-package OOXML xl/embeddings/tEkI.qQoFO3 Ole10Native stream: OLe10naTiVE 1009592 bytes