Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 1a94b36bd3f029da…

MALICIOUS

Office (OOXML) / .XLSX

346.1 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 8728a0e84629e17938292a7ae8068a8f SHA-1: da7f24acad3e51d2cc54bd6893cb28d6d388efa5 SHA-256: 1a94b36bd3f029da53ff4bade35f5841fc0a0dc9d95db565a00727dc1b949a52
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing Excel 4.0 macros, indicated by the OOXML_XLM_MACROSHEET heuristic. The macrosheet content is heavily truncated and obfuscated, preventing a detailed analysis of its specific actions. However, the presence of such macros strongly suggests an intent to execute arbitrary code, likely for malicious purposes such as downloading further payloads or establishing persistence.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
6c9c9046a70460e04fd3696ffd746b609980cb5b0f627f75fe4386634fa0bfc8
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 264327 bytes