Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 4dea495d5c1c5e0c…

MALICIOUS

Office (OOXML) / .XLSX

95.0 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 91eca239ee8b604f18f6fb1ed6cde135 SHA-1: 78c47637b513d11ba6c36b19b9d79f7ee7a86338 SHA-256: 4dea495d5c1c5e0cb56677608b5efa53658cc20bb836f9cccd2aa1092b573aa8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing a macro sheet, indicated by the OOXML_XLM_MACROSHEET heuristic. The macro sheet itself is heavily truncated, preventing a full analysis of its behavior. However, the presence of Excel 4.0 macros suggests an attempt to execute commands or download further payloads. Due to the truncated nature of the macro sheet, the specific commands and their intent cannot be fully determined, leading to a lower confidence score.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
53c30c0fd4dced39aaa64ddc7fe42983f0f769c9723db78e0971634328370091
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4094 bytes