Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 12d7414b3f0181a5…

MALICIOUS

Office (OOXML)

9.5 KB Authoring application: 14.0300 First seen: 2021-02-23
MD5: ea820e48aad7a3ce14bc5e6e322b6a31 SHA-1: de03d09e81f17daea36e730134c0e0b3e501d8c3 SHA-256: 12d7414b3f0181a5e4006902d6a63b93bad2569faad5734b944c79d51c15cda1
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.