Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 3fb6b4f7749a5fd6…

MALICIOUS

Office (OOXML) / .XLSX

85.2 KB Created: 2021-03-15 18:27:04 UTC Authoring application: Microsoft Excel 16.0300
MD5: eec048ecda6c67c0c3e4d9efb431bb72 SHA-1: 248a6b1656c51511fd0e2d98033493c7382d1ddc SHA-256: 3fb6b4f7749a5fd6a49cbadd6a7e14fa786d24e4c4bd110565127221e702da3b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing Excel 4.0 macros, indicated by the OOXML_XLM_MACROSHEET heuristic. The extracted macro content is heavily obfuscated and truncated, making it impossible to determine the exact payload or download URL. However, the presence of Excel 4.0 macros strongly suggests an attempt to download and execute a secondary malicious payload.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
45a18ac53fcd8ba96afbd4dd7e3f6e47f6d5efd44fcf2dfe104479d482e2021e
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 92701 bytes