Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 082f292eff9ed2b4…

MALICIOUS

Office (OOXML) / .XLSX

136.1 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 290a5b28a1d973bdc0d6de5612a7a72f SHA-1: 0621b16c7cda25d51995f6eb90eb9c85ffaeba91 SHA-256: 082f292eff9ed2b422eb4beb14f4b2adfad93b855b9693a1e01ab3f4f3146c22
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The file is an Excel spreadsheet containing Excel 4.0 macros, which are known to be used for malicious purposes. The heuristic firing indicates the presence of these macros, suggesting an attempt to execute arbitrary commands. The macros are likely used to download and execute a secondary payload, a common technique for initial access and further compromise.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
a932d6b610eaa2a22e1d952b85c227c363b27a8f4145e7801de3195621ac2952
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 623799 bytes