Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 ff46b7675e4e6650…

MALICIOUS

Office (OOXML) / .XLSX

12.1 KB Created: 2021-02-14 05:51:27 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2022-06-14
MD5: 1ccca1522040a59b1f4e23bb5c10eec7 SHA-1: 885463fb57778891eab3d6dc9dd041da602b4a84 SHA-256: ff46b7675e4e6650461260039775593214e69be1141588a79bb8674558d99473
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The sample is an Office document containing an embedded OLE object that triggers CVE-2018-0798, a vulnerability in the Equation Editor. This indicates the document is designed to exploit this vulnerability for arbitrary code execution upon opening. No document body text or scripts were extracted, but the presence of the vulnerable OLE object is sufficient evidence for the attack pattern.

Heuristics 3

  • Equation Editor OLE object high CVE related OLE_EQUATION_EDITOR
    Embedded OLE object xl/embeddings/oleObject1.bin contains the Equation Editor CLSID, the legacy component exploited by CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798.
  • CVE-2018-0798 — anomalous Equation Editor native stream high CVE likely CVE_2018_0798_EQUATION_NATIVE_ANOMALY
    Embedded Equation Editor OLE data contains anomalous native stream bytes consistent with a CVE-2018-0798-style Equation Editor exploit. This is treated as likely CVE evidence because the Equation object is malformed and payload-like, but it does not match the exact public matrix-overflow byte signature.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
82c85155b8c8410b77a98a562650d67c136fbc4f135a2cc2596d4d822f3599ef
ooxml-ole-object OOXML embedded OLE part: xl/embeddings/oleObject1.bin 4096 bytes
ooxml_oleobject_00_ole10native_00.bin
d7e17dec907e6d7515ae309668e9fb40964eddc885aca1473ed57923d9b6184b
ole-package OOXML xl/embeddings/oleObject1.bin Ole10Native stream: olE10NatIve 1564 bytes