Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 41cae704ec5ddb77…

MALICIOUS

Office (OOXML) / .XLSX

99.3 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 22ed6da91b890549598b6d29abfdb404 SHA-1: 5b37493467cfbf7839cd8bfc3703ab8eb72deefa SHA-256: 41cae704ec5ddb77d1ed6cb2e3f8f70cf775f5a303fa156c92489e38848d1051
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel 4.0 macro sheet, indicated by the OOXML_XLM_MACROSHEET heuristic. Excel 4.0 macros are known to be used for executing arbitrary commands, which can lead to the download and execution of further malicious payloads. The macro content itself is heavily obfuscated and truncated, preventing a more detailed analysis of its specific actions or the reconstruction of any URLs or commands. Therefore, the exact attack pattern and family remain uncertain.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
1e2966aa3faeeb78195f3c3c426177ca9dbba2bef1d86a4646b04d86379bfb67
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 6396 bytes