Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 05b4ef60fbfac308…

MALICIOUS

Office (OOXML)

8.4 KB Created: 2017-10-15 13:53:03 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2021-05-04
MD5: 0dcd0423b0e44ed4309751735e0ba09a SHA-1: 5361a2b344d137bd8041e3c7d264bbb0d72a9417 SHA-256: 05b4ef60fbfac3088878c6e84930484f830cf4c8180013a7021ac52bdcc578c2
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.