Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 591940ca336ef770…

MALICIOUS

Office (OOXML) / .XLSX

124.5 KB Created: 2022-10-07 13:16:26 UTC Authoring application: Microsoft Excel 16.0300
MD5: 119bf0e1edae72a7920cc2211ae08d33 SHA-1: 1922542a0580c6fe523cbb374d9ee70ce7ef4456 SHA-256: 591940ca336ef7709d0dc6dbfe99e36acc7741456973f7d3fdfb98632d6c6ce4
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The critical ClamAV heuristic indicates this XLSX file is detected as a phishing variant. The presence of an external hyperlink to a SharePoint URL further supports this, suggesting the document is designed to trick the user into navigating to a potentially malicious external resource. No scripts were extracted from this sample.

Heuristics 3

  • ClamAV: Xls.Phishing.Generic-10042509-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Phishing.Generic-10042509-0
  • External hyperlinks (1) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 1 external hyperlink — clickable URLs are stored as external relationships. First target: https://mycoretherapy-my.sharepoint.com/:f:/p/mark_jenkins/EsaPkwjgXbZHikwJS6qdBV4BewAV4Cguf9qAV_GUvXqJVw?e=kmR6mA
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/exif/1.0/
    • http://schemas.openxmlformats.org/spreadsheetml/2006/main
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.microsoft.com/office/spreadsheetml/2009/9/ac
    • http://schemas.microsoft.com/office/spreadsheetml/2014/revision
    • http://schemas.microsoft.com/office/spreadsheetml/2015/revision2
    • http://schemas.microsoft.com/office/spreadsheetml/2016/revision3