Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2fed87067710c99b…

MALICIOUS

Office (OOXML) / .XLSX

107.8 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000 First seen: 2021-11-07
MD5: cdfe15ba79f46ff0c5f8ff6a1b72d8f7 SHA-1: 2f66bcc066b642b92e0cde42ff43e3ebe7d38168 SHA-256: 2fed87067710c99b733c10534961d404b52bee981643315a289bb39a5f6fea3b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing an Excel 4.0 macro sheet, identified by the OOXML_XLM_MACROSHEET heuristic. This type of macro is capable of executing arbitrary commands. While the specific commands are truncated and obfuscated in the provided excerpt, the presence of an XLM macro sheet strongly suggests an attempt to download and execute a secondary payload. The file's metadata indicates it was authored by Microsoft Excel.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
6147b04a1f86cf32dcf789250ce057b0cfefb817674caa528cc14f08c901140a
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 280376 bytes