Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 15f2ebf7b4f37340…

MALICIOUS

Office (OOXML) / .XLSX

81.3 KB Created: 2021-02-26 07:53:41 UTC Authoring application: Microsoft Excel 16.0300
MD5: 27a3ac1a3832b83300ff20a2d0d86337 SHA-1: 5f519f318a6848cd7735c30a7b25452c44b43c53 SHA-256: 15f2ebf7b4f37340c55a97d24771f27d685cb92991172f4eabca0986d0727581
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. These macros are known to be used for executing arbitrary commands, often as part of a spearphishing attachment to gain initial access. The specific macro sheet is identified as xl/macrosheets/sheet1.bin.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
ae514a8be97fee1a74d1b9487b34e70de34bf0bb0235b54f947067978948fe90
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4569 bytes