Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 17226015998bc93e…

MALICIOUS

Office (OOXML) / .XLSM

426.3 KB Created: 2004-08-16 18:44:14 UTC Authoring application: Microsoft Excel 15.0300
MD5: 03bd9aad3d17ed0666f5d6c2924afbea SHA-1: 9497dd028d381a0bca7315d3a33348f00342c148 SHA-256: 17226015998bc93e20717e039ee9802c9cef1ee754d3925225d99cc521deded4
210 Risk Score

Heuristics 8

  • NOP sled detected high SC_NOP_SLED
    Found 20+ consecutive 0x90 bytes
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • GetObject call high OLE_VBA_GETOBJ
    GetObject call
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains a VBA project — VBA macros present
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • External hyperlinks (1) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 1 external hyperlink — clickable URLs are stored as external relationships. First target: https://www.vertex42.com/ExcelTemplates/quote-template.html
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.purequestair.co.za/
    • https://www.vertex42.com/ExcelTemplates/quote-template.html
    • https://www.vertex42.com/licensing/EULA_privateuse.html
    • https://www.vertex42.com/ExcelArticles/invoicing.html

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
8b504c83ba544c694cf14287ca9fd9183aa10798e0df50d53fc93870ff5bc5f8
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 3474 bytes
vbaProject_00.bin
b60b7d0fe394fef8f5297abf2c4dab9929f6fd38a15ead2a87d8717951d2d336
vba-project OOXML VBA project: xl/vbaProject.bin 17408 bytes