Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 429f3f72427426ba…

MALICIOUS

Office (OOXML) / .XLSX

86.9 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 31df932d552eadd89fd572444f1211cc SHA-1: 0b1fdfefe92323aaf94028e45fb19521d6595524 SHA-256: 429f3f72427426ba8976bf9f315ccfbd6bfa46c681f571a63b779218c7272b3b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. These macros are known to be used for malicious purposes, such as downloading and executing further payloads. The extracted macro content, though truncated, shows a path that appears to be an attempt to write to a file named 'excel.rtf' in the 'C:\ProgramData\' directory, suggesting a downloader or initial stage payload.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
882047485b95d104534106c33f8b0817a6a13c8427cbd86a80796fe58aa5b862
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 96586 bytes