Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 315b0dd8a8ccd950…

MALICIOUS

Office (OLE) / .XLSX

36.0 KB Created: 2020-11-25 10:36:27 Authoring application: Microsoft Excel
MD5: 6c518f706cdc90e93f9c0d5e7f57720a SHA-1: 916a0915cea87ab7870f2f1f38ce72f187779b0a SHA-256: 315b0dd8a8ccd950c0230bf4049bf5755bd6101d40ca23b0cbc4bbb7b476ded3
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1566.001 Spearphishing Attachment

The file contains Excel 4.0 macros, specifically an Auto_Open defined name, which is a critical indicator of malicious intent. The presence of dangerous formula APIs like RUN further supports this. The macro sheet likely contains obfuscated code designed to execute commands or download further payloads. The document body contains a large amount of seemingly random characters, which could be part of an obfuscation or decoy strategy.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
d1035aad90d980a23d4d83f7a14e92e2f32f7f3a3b5d29454164f9b91ce50332
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6468 bytes