Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 0f99b4bac6c435c0…

MALICIOUS

Office (OOXML) / .XLSM

106.9 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3d12a55adfd0f7e6eaec6b467dc91c3f SHA-1: 913155435a6fdedeb7a5898b4c94023307d2a244 SHA-256: 0f99b4bac6c435c04f8dd49b1ff39f6907c0c267a778f5f4ad356211f1b68037
182 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.005 Visual Basic T1203 Exploitation for Client Execution

The sample is an Excel 4.0 macro sheet (XLSM) that uses dangerous functions like CALL and EXEC, indicating an attempt to execute arbitrary code. The embedded URLs in the document body are likely part of a social engineering lure to trick users into visiting a malicious site for further compromise. The Auto_Open defined name suggests automatic execution upon opening the file.

Heuristics 4

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks.
  • Excel 4.0 Auto_Open defined name critical OOXML_XLM_AUTOOPEN_DEFINEDNAME
    Workbook defines _xlnm.Auto_Open or _xlnm.Auto_Close while containing an XLM macro sheet. This is the OOXML/XLSB auto-execution shape for Excel 4.0 macros.
  • Dangerous XLM formula APIs: CALL, EXEC, FORMULA.FILL, HALT critical OOXML_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet uses formula APIs that call directly into Win32 (=CALL/=EXEC/=REGISTER/=FORMULA). These are the primitives used to download payloads, write files, and start processes from an XLM macro without invoking VBA.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/spreadsheetml/2006/main
    • http://schemas.microsoft.com/office/excel/2006/main
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.microsoft.com/office/spreadsheetml/2009/9/ac

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.xml
9cf577639483a84c18a4933d3e27f255a331eea77d6198cb6ba582a5fa65de0a
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet1.xml 240381 bytes