Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.
Static analysis of two malicious Office files, done entirely inside an isolated REMnux VM. Nothing was ever executed — just inspected.
SHA-256: 68e82279bff55cf3b9f1f22ec4a165b1b1245a359f7e8d86664b2541d8f8d3fe
What I found:
nste.xml) was actually Rich Text Format data pretending to be XML — a mismatch that's a red flag on its own419876.vbs)Verdict: Malicious. This is a real weaponized document using a known RCE to drop an executable.
SHA-256: dc65419ba5d83b980d7018198a14209fa2f5ebf6f99d47bfe9f586852087befe
What I found:
mraptor returned "Macro OK" with no AutoExec/Write/Execute flagsVerdict: Suspicious, but inconclusive. The encryption, hidden sheet, and obfuscated strings all look like evasion tactics, but I couldn't confirm an actual live payload in the VBA layer. The real payload may live in the legacy XLM macro layer (which I didn't fully reverse), or this could be an incomplete/staging sample.
file, compare to the extensionoleid for a quick read on encryption/macros/external linksoledump to list every embedded objectolevba to pull and decode any VBA sourcemraptor to check for auto-running macro behaviorMofolorunsho Adeleke GitHub: https://github.com/Mo200909