Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 3110ca3a3f271be4…

MALICIOUS

Office (OOXML) / .XLSM

76.9 KB Created: 2020-06-17 09:25:59 UTC Authoring application: Microsoft Excel 16.0300
MD5: 8aab6782589a9d59d7ee752bce795420 SHA-1: a8cf50716a9c9587279200cfb37ebb208edcc6a8 SHA-256: 3110ca3a3f271be4e055a24fb49ae3f35646cea6f99d356ea6672a3f705dcbb5
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.003 Windows Command Shell T1204.002 Malicious File

The sample is an XLSM file containing VBA macros. Heuristics indicate the use of Shell() and CreateObject() calls, along with WScript.Shell, suggesting the macro attempts to execute commands or launch external processes. The presence of embedded VBA macros and the critical heuristic firings strongly indicate a malicious intent to run arbitrary code, likely for downloading and executing further malicious content.

Heuristics 5

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
1b920a189baa8f7da53c366060684343429be06acafc9379d3e463b4ef6b2545
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1109 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s).
vbaProject_00.bin
ac6f52e63c40efa0189bef9549d411339227ddb13257fbd7376833205f4d60e0
vba-project OOXML VBA project: xl/vbaProject.bin 15360 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s).
emf_00.emf
fecfe179ff2b97f835db12f78ddb379fa853a64b4aaa1cb5b029f82caacc6015
ooxml-emf OOXML EMF part: xl/media/image1.emf 1976 bytes