Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 f36816c3559b267a…

MALICIOUS

Office (OOXML) / .XLSX

586.5 KB Created: 2023-08-03 11:34:29 UTC Authoring application: Microsoft Excel 16.0300
MD5: 686b91cd1edc9b359400b9601f97b256 SHA-1: 191f27ef4002a0a45aa748fd18e5f0e4617f8fe2 SHA-256: f36816c3559b267a525841a1c3fd98c52a4507f2a692589874ba55e7abf7d513
60 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking

The high-severity heuristic firing for 'Equation Editor OLE object' indicates the presence of a known exploit vector within the embedded OLE object. This technique is commonly used to execute arbitrary code by exploiting vulnerabilities in the Equation Editor component. The embedded OLE object itself is the primary indicator of compromise.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/7SLcxgfwQ.Afk contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
6ccac23e105e505e4b2d692f8e118ff55625872aaaf14ad3d692488c3189f792
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/7SLcxgfwQ.Afk 839168 bytes
ooxml_oleobject_00_ole10native_00.bin
5a2678c65c84b007c3850fff57eca796444a6ab906f433f5b2c36cd6479ed845
ole-package OOXML xl/embeddings/7SLcxgfwQ.Afk Ole10Native stream: Ole10NaTIVe 830139 bytes