Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 45b7fdc227356857…

MALICIOUS

Office (OOXML) / .XLSX

91.8 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: dad2113df6ae0dbf7f1beddacd0fb30c SHA-1: 652be44102ddf89402854ce678a1ef481a9e425b SHA-256: 45b7fdc227356857c972281530fe2b3f92804bc563e640a411035dd51d2abd9e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing a macro sheet, indicated by the OOXML_XLM_MACROSHEET heuristic. Excel 4.0 macros are known for their ability to execute arbitrary commands, often used for initial access or payload delivery. The macro content itself is heavily obfuscated and truncated, preventing a more detailed analysis of its specific actions or payload. However, the presence of the macro sheet strongly suggests a malicious intent to execute code.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
aca13cee4d2c4330012d1585d1d380cc4d38dc03a452e653c26a477a93469eff
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 7915 bytes