Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 314c7b0bfe6cfa6b…

MALICIOUS

Office (OOXML) / .XLSX

67.3 KB Created: 2021-03-14 21:03:54 UTC Authoring application: Microsoft Excel 16.0300
MD5: cdf0c5cad31be82c68203aa04aa20292 SHA-1: 3f9a1284e68d3a79cabc4fb53fb8ff3827427791 SHA-256: 314c7b0bfe6cfa6bfc1dc3b16e5a3b124b7c8e639f0b908bb1771ac5984f50cb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is heavily truncated and obfuscated, the presence of such macros strongly suggests an intent to execute arbitrary code. This is commonly used to download and run a second-stage payload.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
0879e3a33fe7a9661a2e275f7c09850372c1d3eb00616716182006ef80186cd8
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 92099 bytes