Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2b1206d427d4676f…

MALICIOUS

Office (OOXML) / .XLSX

116.6 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: aec46d8da7a1c5e06d6ceadb8691dbe3 SHA-1: 477a896c207c3b1ebc866f9862aa481bcf8c001c SHA-256: 2b1206d427d4676f608ce841f7e847fd9949ab8457d66a3071e9408321e86434
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing embedded Excel 4.0 macros. The heuristic firing indicates the presence of these macros, which are often used to download and execute further stages of malware. The macro content is heavily obfuscated and truncated, preventing a detailed analysis of its specific actions or the reconstruction of any URLs or commands. Therefore, the exact attack pattern and IOCs cannot be definitively determined.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
488bfde05804e6bc40c7642908a1d89b3c1ec08d4194878e6b1de809bcd5a97f
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 205574 bytes