Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 f5eeb56fa4c609e1…

MALICIOUS

Office (OOXML) / .XLSX

679.9 KB Authoring application: Microsoft Excel 12.0000
MD5: a278c0370e95b81fed05f5f16cd482c0 SHA-1: af710a7cba9e1770a71b70889d8930d516241586 SHA-256: f5eeb56fa4c609e146563f5f7a9798f34845455f039245b95fa9e436e453ed96
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file contains an embedded OLE object, specifically identified as an Equation Editor object, which is a known vector for exploiting vulnerabilities like CVE-2017-11882. This technique allows for arbitrary code execution upon opening the document. While no scripts were extracted, the presence of the vulnerable OLE object strongly suggests an exploit attempt aimed at delivering a secondary payload.

Heuristics 2

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/Eg9.kH contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
e9315d1ad26aa70510f310b855ab3ba016d74546877b801c1718e1072a7ab980
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/Eg9.kH 958976 bytes
ooxml_oleobject_00_ole10native_00.bin
e7e927cb437221bc1caabf87d135c64ad42f68941ec81f12781536d160d2ee2b
ole-package OOXML xl/embeddings/Eg9.kH Ole10Native stream: oLe10NAtIVE 949248 bytes