Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 359c7c6c83047289…

MALICIOUS

Office (OOXML)

9.0 KB Created: 2017-10-26 07:56:11 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2022-07-25
MD5: 13fb5902e80484db65fdc693d3c893ae SHA-1: 60b4bacd1ad599991e1ec0e9a2ba2de4b90cd313 SHA-256: 359c7c6c830472894a094acb85afcc6ea53e9d23e3e1d858180711abf2fb916a
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.