Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 22230976df2fc29a…

MALICIOUS

Office (OOXML) / .XLSX

74.0 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 5d31da137b685aa1cf447af57d855fe7 SHA-1: e2734ba91c0d6f392417034e0c8cd01e24b4af6f SHA-256: 22230976df2fc29a01ea47b0dcdee6221d53471c3b4bad8442f3a32cf3bf3b55
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is truncated, the structure suggests it is designed to execute commands. This is a common technique for downloading and running additional malicious content. Without further deobfuscation or content, the specific family remains unknown.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
7ed2b2d216e835daab21488af6bdd61532dd244894a51211bfa30adde7f8b8e1
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 7887 bytes