Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 30a27f834183c2c9…

MALICIOUS

Office (OOXML) / .XLSX

79.7 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: a8b05f0781be741710594ec8616540c7 SHA-1: fac6283173d33ac0ec42603afbf7c0af18bf7bee SHA-256: 30a27f834183c2c94d01d18838bed678f78aa07a09ba5cd1aec57416ef18a43e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros, a known technique for delivering malware. While the macro content is truncated and heavily obfuscated, the presence of this macro sheet strongly suggests an attempt to execute arbitrary code, likely for downloading a second-stage payload. No specific family could be identified.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
93a75e57e67da515b3233745c9522bab0041ef3898b5fcff9997f6486c8b613d
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 5377 bytes