Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 3fa229da3e1c5ce9…

MALICIOUS

Office (OOXML) / .XLSX

78.0 KB Created: 2021-03-14 20:07:32 UTC Authoring application: Microsoft Excel 16.0300
MD5: 18d76d25506af72b18ef082967d87f77 SHA-1: 694b49a0ab22e7f06734c6a3c3898f19e84ccd68 SHA-256: 3fa229da3e1c5ce9e890539c534d87bd94af56c1dfa50669fcf19914a8fb6b22
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. While the macro content is heavily truncated and obfuscated, the presence of this type of macro sheet is a strong indicator of malicious intent, typically used to download and execute further stages. The file is an Excel spreadsheet, and the macro sheet is the primary artifact suggesting malicious activity.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
9419d3d4d0b5c74f0a727ba07d353bb5847c2c09ac10a25d060a78e7e686fa6f
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 95594 bytes