Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 163a845f48ed69ae…

MALICIOUS

Office (OOXML)

10.0 KB Created: 2021-03-18 03:05:57 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2021-04-01
MD5: 064b72546b347dd038210d10b665960a SHA-1: e62ece051f2f83a238f94a463a762bc468b160f4 SHA-256: 163a845f48ed69ae9c79cefb7b56957819a90e0ab190e79b2e443e4becb323f9
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.