Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 582bd8cb4f80cbc6…

MALICIOUS

Office (OOXML)

18.3 KB Created: 2021-01-11 20:06:02 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2021-01-23
MD5: 392e094d609e50add733faaf3331c36b SHA-1: 3130d0cf68aaf7daf7415b556ef0c933e5ce1be6 SHA-256: 582bd8cb4f80cbc634d3fa224fea0b12df42a974f01f3de70e830d4920482ac1
62 Risk Score

Heuristics 2

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lnut1.sytes.net:4442/script.txt In document text (OOXML body / shared strings)