Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 316e19fe0222dfaa…

MALICIOUS

Office (OOXML) / .XLSX

357.4 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: e6e19f59f414cfe3c767ce6e2dfc2497 SHA-1: dbf6874ed2f70e609aff455d417a67d7e77251cc SHA-256: 316e19fe0222dfaaffb7acc37c7df2944258d7851ccbb32ecc6c7b1ad9623689
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. While the macro content is truncated, the presence of such macros is a strong indicator of malicious intent, typically used to download and execute further stages of an attack. The specific commands are not fully recoverable due to truncation, limiting the ability to identify a specific family or precise IOCs.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
228c23c54ebc5c328b553f9886989ac862cc5d4bdfc45ef79b36269f33a048e2
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 227755 bytes