Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 52b330f16d858c74…

MALICIOUS

Office (OOXML) / .XLSX

98.9 KB Created: 2021-01-31 17:47:11 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2021-02-23
MD5: 2ec72f5e2212c6b28398c63262dea005 SHA-1: 7c457be5bd44fcb6ede6a53ca33071a55555ed2c SHA-256: 52b330f16d858c74fef8c1b1917d8db589fc58965d076ec8ed31d9592f534b88
60 Risk Score

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 2109 bytes
SHA-256: 8964e04936837a1436fedbb98654f235a472b1dd62b52ea1c5cc2d350d9138ef
Preview script
First 1,000 lines of the extracted script
�  �  �   @      ��������    �      3           �  %      ��                  & �  �     $       @   d           � $    ?               ?   ?           �  �  %      ��    & �  ����  ,     �  <          )        <     �?  $	        �  �  %      ��    &           ,                          c   %      ��    &           ,                          d   %      ��    &           ,                 &               I   @  #    #          %      ��    &           ,                          e   %      ��    &           ,                             
    @  CH        %      ��    &   
       ,                          f   %      ��    &           ,                          g   %      ��    &           ,                          h   %      ��    &           ,                          i   %      ��    &           ,                          j   %      ��    &           ,                          k   %      ��    &           ,                          l   %      ��    &           ,                	E                  +   Z  |    �:  z    �:  �    �:       �   B �     %      ��    &           ,                
:           '       AJ  @     0 0 : 0 0 : 0 3  @   B ��    %      ��    &   "       ,                
D           1   Z  �    �Z  Z    �Z  �    �   Z B Z T      	 B �     %      ��    &   #       ,                 7           $   #~      :      	�:       �      B �     %      ��    &   )       ,                
:           '       AJ  @     0 0 : 0 0 : 0 3  @   B ��    %      ��    &   /       ,                
D           1   Z  �    �Z  �    �Z  �    �   O L E R      	 B �     %      ��    &   0       ,                 D           1   #R      :  �    �:       � @  :  #   	�      B �     %      ��    &   3       ,                
                B 6     �  � � ��                                                                  @   �ъ�a>��� #6W������o&��5��� 6���=��~1_��5G3�/�Ic1z�7 W�������     LZ�ԥ��+ �V�˪�    S H A - 5 1 2 � B                                                                  �  ��� 0ffffff�?ffffff�?      �?      �?333333�?333333�?%      ��                  & �