Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 444a0953b513aaad…

MALICIOUS

Office (OOXML) / .XLSX

68.6 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 47ee46b3521d1f85743ab56ac8c4f4b3 SHA-1: a4b5e087009458f9a6a0e6f7b2e8ebbb261233f9 SHA-256: 444a0953b513aaad678d37e960dd7fe5841025e0bebf2e71eb350d4709a0f34f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic 'OOXML_XLM_MACROSHEET' indicates the presence of Excel 4.0 macros. While the script content is heavily truncated and obfuscated, the presence of such macros strongly suggests an intent to execute arbitrary commands. The reconstructed IOC 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\a.exe' points to a likely payload dropped into the startup folder for persistence.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
1a003fa25d38db5893c657854338d7c4259a1f9c9f8bbb002e2a8b0891f46440
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 7400 bytes