Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2a5e126d19a9ec44…

MALICIOUS

Office (OOXML) / .XLSX

73.8 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 1ee57c2eb43f834998b83f28329712f5 SHA-1: 81e1a629a259a827536cb59972e10b6972971d1d SHA-256: 2a5e126d19a9ec44c7436e648c7e2c2eecaa9006768ef994cce127ed86858cb1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are designed to execute arbitrary commands, and the extracted path 'C:\ProgramData\excel.rtf' suggests an attempt to drop and execute a malicious file. The macro content is heavily obfuscated and truncated, preventing a more detailed analysis of its specific actions or the exact payload it attempts to download.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
e468b73945297bf78e5cd8ba703820080ae20698fcbe8e3f6dbd7da59162a071
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 145316 bytes