Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 44c5aca8dc1e487f…

MALICIOUS

Office (OOXML) / .XLSX

86.6 KB Created: 2021-03-15 18:20:11 UTC Authoring application: Microsoft Excel 16.0300
MD5: 1ad65dab80a62c9c724a2f1a6c3c0a82 SHA-1: 6fb13348b84f13e23c27e446a3f7fd4013aafbfe SHA-256: 44c5aca8dc1e487f9c620341d2e8a640143b0428bea4387c77a8a68004fd3bc4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel document containing a macro sheet, identified by the OOXML_XLM_MACROSHEET heuristic. The embedded XLM macros are heavily obfuscated and truncated, making it impossible to determine the exact payload or execution flow. However, the presence of XLM macros strongly suggests an attempt to download and execute a second-stage payload.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
3b30b847ecb3aee3c97475515d4b1ac5ef6cb473175a1f0b3906a981ea7cf456
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 96434 bytes