Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 144e904f21e547c0…

MALICIOUS

Office (OOXML) / .XLSX

103.8 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 8a7b8bae3d9860e341af04b60a5c6c59 SHA-1: fde47bed54196333ed7694527b7f5fe48e231e51 SHA-256: 144e904f21e547c079a1b9280ebf5aa3d1164bfd9f904890aea4a1d90bbcf443
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing Excel 4.0 macros, indicated by the OOXML_XLM_MACROSHEET heuristic. The macros appear to be obfuscated but contain references to a path that suggests the execution of a secondary payload, likely 'a.exe' from 'C:\ProgramData\'. This indicates a downloader or dropper functionality.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
43e1a93d4bfa91e644b3044d16278c48be6cb12bf623d0934b85b3ef0d29a981
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4546 bytes