Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 274be08984ed7ff6…

MALICIOUS

Office (OOXML) / .XLSX

74.2 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: b35c99a8622cd401bdf10a11d5f4c76f SHA-1: e722b081eec3ee2a50bb36ebf7efa90d524496c9 SHA-256: 274be08984ed7ff6676180d2871208a4bf864899237aeb7958f10c40bbd9f8e8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing an Excel 4.0 macro sheet. This type of macro is known to be used for executing arbitrary commands. The macro sheet itself is heavily obfuscated and truncated, preventing a detailed analysis of its specific actions. However, the presence of the macro sheet strongly suggests an intent to execute malicious code upon opening.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
4e743f133770f7387939b2a1f8fa2db43db174dddc8d1aa1f148cacb16a41537
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 7180 bytes