Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 126a5bb68199565e…

MALICIOUS

Office (OOXML) / .XLSX

372.5 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: e41a1c0d096bd6a658cf781f40ac33c1 SHA-1: ab258088573133508ff188269a94b039ca1b7473 SHA-256: 126a5bb68199565e38f184a8269eb5dc52dab0db837aa1a5fddacc52ac448349
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The file is an Excel spreadsheet containing Excel 4.0 macros, which are known to be used for malicious purposes. The heuristic firing indicates the presence of these macros, which can be used to execute arbitrary commands. The macros themselves were truncated, preventing a full analysis of their specific actions, but the presence of XLM macros strongly suggests an attempt to download and execute a second-stage payload.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
31b0a945ae5de37ce6d68b00d975fa2b49370857823c73c05b0422404744c819
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 625211 bytes