Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 500856ee3fc13326…

MALICIOUS

Office (OOXML) / .XLSM

182.6 KB Created: 2021-10-04 13:17:51 UTC Authoring application: Microsoft Excel 16.0300
MD5: 3e27d372e454366e906fe821070608bb SHA-1: be4d41456335670e78c6e3f19eb2fbd4c6a9a84f SHA-256: 500856ee3fc13326cad564894a0423e0583154ef10531de4ab6e6d5df90d4e31
108 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1140 Deobfuscate/Decode Files or Information

The sample is an XLSM file containing VBA macros, specifically a Workbook_Open macro designed to execute automatically. The script reconstructs a URL 'http://e.if.m/l.p' and a DLL path 'C:\Users\<user>\AppData\Local\think-cell\test.dll'. It also attempts to establish persistence by writing to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAccessible2Proxy'. The script's primary function appears to be downloading and executing a second-stage payload from the reconstructed URL.

Heuristics 4

  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
7b6e93eba72973e333189a6c66f741c101ddf18cd055cfa996507316045ac9d9
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 2925 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
4a73b03a4d8d38ac9890bcd427ff8aa02e3cad0508817aec4362735d46913ae1
vba-project OOXML VBA project: xl/vbaProject.bin 14848 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.