Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 2ae3894e16d96d5a…

MALICIOUS

Office (OOXML)

62.0 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2021-06-17
MD5: 84247a8a3ffdce32f58b8bed73b8adcc SHA-1: 235c10ca7b5f9b41f0549620ae1c6ca8eac8be71 SHA-256: 2ae3894e16d96d5a1d8be0f7fd4dc674f5a54985af016ef095037f8bffdd92c3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros, which are known for their ability to execute arbitrary commands. The truncated script content suggests obfuscated macro code, typical of malware designed to download and execute further stages. Without more script content, the exact payload and delivery mechanism remain unclear.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet1.bin 1811 bytes
SHA-256: c03a19a43999132e3e943a64d9f09c145c1ff1f3e7ec64136db086ccbbd870ca
Preview script
First 1,000 lines of the extracted script
�  �  �   @      ��������    �      P   *   M   �  �  �             @   d           � $                                    �  �  %      ��    & �  �     ,     �  <     �?  �         �  �  %      ��    &           ,        =   M     =       
   %      ��    &           ,        =   M     =           %      ��    &           ,        =   M     =           %      ��    &           ,        =   M     =           %      ��    &           ,        =   M     A       
   %      ��    &           ,        =   M     F       	   %      ��    &           ,        =   M   	EM            �@@  +   Z  H   >�Z  I   >� Z  J   >� Z      A� B n     %      ��    &           ,        =   M     =             A           %      ��    &           ,        =   M   
 M              B 6     %      ��    &           ,        *   *   	� *                 �   D    =�D    A� DA   E�DD   E� DG   K� DG   M� D    F� DP   C�DH   K� $?   H�D    =�D    =� D    =� D    =� $    A�$D   H�$G   H�B �     %      ��    &   !       ,        *   *   
 *          
   :      M�B �     %      ��    &   ?       ,        H   H     H           %      ��    &   A       ,        >   M     E           %      ��    &   D       ,        >   M     E             H           %      ��    &   G       ,        >   M     H             K             M           %      ��    &   H       ,        >   M     >             K           %      ��    &   I       ,        >   M     >           %      ��    &   J       ,        >   M    9>           v r 3 2   - s            v r 3 2   - s       %      ��    &   P       ,        C   C     C           �  � B                                                                  �  � � 0ffffff�?ffffff�?      �?      �?333333�?333333�?� .	   d   X   X                         r I d 2 %      ��                  & �