Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2a7fadfd79294f90…

MALICIOUS

Office (OOXML) / .XLSX

106.1 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 923db97bea22784bdddeed9fcd41ae11 SHA-1: 21711688a78dd659029ef20ff169e2304163ee36 SHA-256: 2a7fadfd79294f9046067dafdef3e9eeb38a3e46461749c1f12d11d7c84f60d3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing embedded Excel 4.0 macros. The critical heuristic firing confirms the presence of these macros, which are often used to download and execute additional malicious payloads. The macro content itself is heavily obfuscated and truncated, preventing a more detailed analysis of its specific actions or the reconstruction of any URLs or commands. Therefore, the exact family and IOCs cannot be confidently determined.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
c4050efac02add1cf907348ae14cd379a3ee62c1c64718fb61eb86165d0039aa
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 6987 bytes