Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 49571df3567dd31c…

MALICIOUS

Office (OOXML) / .XLSX

61.7 KB Created: 2021-03-14 21:03:27 UTC Authoring application: Microsoft Excel 16.0300
MD5: a872e2984b89d760ca507fb9109639ad SHA-1: 01c18c131ac943985f9179c1136848cfaea4c22f SHA-256: 49571df3567dd31c19324e8c098f2d627af195fcd4be14f7e624a8c73c137ca5
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing an embedded Excel 4.0 macro sheet. This type of macro is often used to download and execute further stages of malware. The macro sheet itself appears heavily obfuscated and truncated, preventing a detailed analysis of its specific actions or any embedded URLs or commands. Therefore, the exact payload and delivery mechanism remain unclear.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
36eaede93e770798ff33597480fc9ff03141f33abb3f4f419ef66c4028d98edb
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 95567 bytes