Emotet — Office (OOXML) / .XLSM malware analysis

Static analysis result for SHA-256 54e18112ee22aecf…

MALICIOUS

Office (OOXML) / .XLSM

104.9 KB Created: 2015-06-05 18:19:34 UTC Authoring application: Microsoft Excel 16.0300
MD5: 410f4844c9b13cb8c21ccade95dbd0e5 SHA-1: d31551135cd48d2be345b8e3aabec9cad68add0c SHA-256: 54e18112ee22aecf58e0f82faf64c55849d05a8f4fab0d2507dbef2cd55ab23b
250 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Service Execution: Visual Basic T1059.001 Command and Scripting Interpreter: PowerShell T1204.002 Malicious Link: Malicious File T1105 Ingress Tool Transfer

This Excel macro-enabled document (XLSM) contains Excel 4.0 macros, identified by the OOXML_XLM_MACROSHEET and OOXML_XLM_DANGEROUS_FN heuristics. The macros are designed to download and execute a payload from one of the provided URLs. Specifically, the macro constructs commands that include 'rundll32.exe' and paths within '\Windows\SysWow64\', indicating an attempt to execute downloaded content. The ClamAV detection as 'Xls.Downloader.EmotetExcel01220-9935623-0' strongly suggests the Emotet family.

Heuristics 6

  • Excel 4.0 macro sheet (7 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks.
  • Excel 4.0 Auto_Open defined name critical OOXML_XLM_AUTOOPEN_DEFINEDNAME
    Workbook defines _xlnm.Auto_Open or _xlnm.Auto_Close while containing an XLM macro sheet. This is the OOXML/XLSB auto-execution shape for Excel 4.0 macros.
  • Dangerous XLM formula APIs: FORMULA critical OOXML_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet uses formula APIs that call directly into Win32 (=CALL/=EXEC/=REGISTER/=FORMULA). These are the primitives used to download payloads, write files, and start processes from an XLM macro without invoking VBA.
  • ClamAV: Xls.Downloader.EmotetExcel01220-9935623-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.EmotetExcel01220-9935623-0
  • Hidden worksheet (hidden) low OOXML_HIDDEN_SHEET
    Excel workbook contains 9 hidden sheet(s) — hidden sheets are commonly used to conceal macro code, staging data, or intermediate payload construction
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/spreadsheetml/2006/main
    • http://schemas.microsoft.com/office/excel/2006/main
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.microsoft.com/office/spreadsheetml/2009/9/ac
    • http://schemas.microsoft.com/office/spreadsheetml/2014/revision
    • http://schemas.microsoft.com/office/spreadsheetml/2015/revision2
    • http://schemas.microsoft.com/office/spreadsheetml/2016/revision3
    • http://schemas.microsoft.com/office/spreadsheetml/2016/revision6

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.xml
8f782d1c76a62d5afae1d19b857a39346fcdece422c7dee0b3af6070b6023819
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet1.xml 3129 bytes
xlm_sheet_01.xml
621787c533e34737d09b762af3d2a152ca75a80fd7e903515df30e29e068d5ff
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.xml 1277 bytes
xlm_sheet_02.xml
ccaa19e55e8e52cf13f8e65f4c0464016a5bbb2dd78136c4f5a5d422e0821ac7
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet2.xml 1274 bytes
xlm_sheet_03.xml
6dc067852be23d26640c1de355c914c45df59bebe3c1a52dc747e56699894d3e
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet3.xml 1277 bytes
xlm_sheet_04.xml
01e958ffeef22a1437f281219fe244bc530807ab3814f515f63924780414a7b7
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet4.xml 1277 bytes
xlm_sheet_05.xml
ded322adab86158705191658c7b8775245eaa06f0ba30473f122bff4e65e1c33
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet5.xml 1277 bytes
xlm_sheet_06.xml
1d2e15e667a637f45c6776b088de7d4d875cfc86dd067b599b02e759fc459f1f
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet6.xml 1274 bytes