Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 19cbabae648cfba0…

MALICIOUS

Office (OOXML) / .XLSX

209.9 KB Created: 2021-09-20 10:27:09 UTC Authoring application: Microsoft Excel 12.0000
MD5: b3941573c6d1965c44e94f5f7feba29f SHA-1: 0563f6719fb3d2707a7592d1705e06fc9085a2d2 SHA-256: 19cbabae648cfba0c00da360fbbd3bd9e5e94833cfe96d9eae8ba8f664097da1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing an embedded Excel 4.0 macro sheet. The heuristic firing confirms the presence of these macros, which are often used to download and execute additional malicious content. No specific URLs or further commands were directly extractable from the obfuscated macro content, leading to a lower confidence in family attribution.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
03390ae5763d670bc2903d2981e7dca74ec59692dc4fe0c8496a822fdf521c36
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 885 bytes