Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 41a1285cb88e7c31…

MALICIOUS

Office (OOXML) / .XLSX

74.9 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 7d0f256871ff67213d676ed37d2a115a SHA-1: f961115e5d314023546d5eac32c9acd9fd627dcb SHA-256: 41a1285cb88e7c3191bbce029843ba0619dad4b905b33252ddc1c3106656a173
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is heavily truncated and obfuscated, the presence of this type of macro sheet is a strong indicator of malicious intent, often used to download and execute further stages. The primary function appears to be command execution via these macros.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
a6dc66d07ca90a677da2c366e6a0efc7fdc7901ae971a446a052a5b82b967b79
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 7303 bytes