Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 45ae12619c81ae06…

MALICIOUS

Office (OOXML) / .XLSX

98.0 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 16.0300
MD5: 8f80f57c941db3d6a9be756712cf4731 SHA-1: f8c29c8855eb684951b4d94dcd906da9eed5ecf6 SHA-256: 45ae12619c81ae06b36c0d8d2bffa1872fa002a75db849ad7115588c8f66f692
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel document containing Excel 4.0 macro sheets. The macros appear to be obfuscated, but the presence of multiple macro sheets and the critical heuristic firing strongly suggest malicious intent. The macros are likely designed to execute commands or download further payloads, fitting the pattern of a macro-based initial access or downloader malware.

Heuristics 1

  • Excel 4.0 macro sheet (3 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
emf_00.emf
ab58818ae1864807b22f8a58a75f7fa8703ecb19a2352bdb47469f366b868e59
ooxml-emf OOXML EMF part: xl/media/image2.emf 1108 bytes
xlm_sheet_00.bin
7ba8c7dae215c3d653270796d8570b3810c64068590cf64325562d684e829370
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 1340 bytes
xlm_sheet_01.bin
cb1f1a0b36df7c5b1ecd6c45b74a2d4711b2827f0ee30f82c9df4f6bc63e617f
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet2.bin 1509 bytes
xlm_sheet_02.bin
ab6060707b634032a9e28cdf4014bbeee5441e8ba06b1724bdb26e4c68089d59
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet3.bin 1296 bytes