Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 5958cb7775ebbdcb…

MALICIOUS

Office (OOXML) / .XLSX

79.3 KB Created: 2021-03-15 18:25:48 UTC Authoring application: Microsoft Excel 16.0300
MD5: 9e72681925e64f5de7c1549c1b9cb3e2 SHA-1: cac2cced890bae7a9ca73702f753c974dc640898 SHA-256: 5958cb7775ebbdcb84a6b278dc5074cad2dd55ce9eb06c7aeed4f08077470bd5
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing Excel 4.0 macros, indicated by the OOXML_XLM_MACROSHEET heuristic. The macro sheet appears to be truncated, but the presence of Excel 4.0 macros suggests an attempt to execute arbitrary commands. Without further deobfuscation or content, the specific payload and delivery mechanism remain unclear.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
ceae90af69b5e0387a5cec25d0382fc755b2c942a71c424445026727072386c2
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 90467 bytes