Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 149e5cdf1caed218…

MALICIOUS

Office (OOXML) / .XLSX

65.3 KB Created: 2021-03-15 18:25:26 UTC Authoring application: Microsoft Excel 16.0300
MD5: 7f6e2a37e0a86f31c4e7fef8e3467ee6 SHA-1: b7ae3b60a29c7f88310eb91383bb96a83f720c57 SHA-256: 149e5cdf1caed21860a8b0ea4b43796ff835063520c4242fbf1b0fae5a801bc3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel document identified as containing Excel 4.0 macros. These macros are often used to download and execute further stages of malware. The embedded macro content is heavily obfuscated and truncated, preventing a more detailed analysis of its specific actions or IOCs.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
1ed9972986d5e39a3ed36602d07bbfd9f1dfd01f866ba4d582a687a8cce3520d
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 97804 bytes