Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2a376d912918bc2f…

MALICIOUS

Office (OOXML) / .XLSX

182.8 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: c44fd51c28ebdfcfe2c0d269cf3d48b2 SHA-1: 7e73beb6ec23bab2f8898c1f8a9506bc2d36a994 SHA-256: 2a376d912918bc2f060051320dffd40b0eb277138ec6e7466f001c65fd666f4e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. The macro sheet contains strings that appear to be file paths, suggesting an attempt to download and execute a secondary payload. Specifically, the paths C:\ProgramData\rd.rtf, C:\ProgramData\lw.rtf, and C:\ProgramData\t.rtf were identified, likely indicating the location where a malicious file would be saved and executed.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
edbbdf2c5751e577f6b124f0dea6421fd936b5dfbfbea92cd974591a0b8e3a81
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4226 bytes