Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 5a33c34cf8e01e90…

MALICIOUS

Office (OOXML) / .XLSX

203.3 KB Created: 2021-09-20 10:27:09 UTC Authoring application: Microsoft Excel 12.0000
MD5: 1664adccd7d0b09956e07ba9cafe3dda SHA-1: 41a7b24fcfd7979f6ef805dfe6357f6a9676dfe0 SHA-256: 5a33c34cf8e01e90aeb70057a45f68d3191393c5bf6258421c9d4bf4b4efece0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are designed to execute commands, which is a common technique for downloading and executing further malicious content. The specific macro sheet is identified as 'xlm_sheet_00.bin'.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
fd93ee16aba86e82c92b64523b3e94edc4685087c429b2560fb0d73baa5c2c95
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 871 bytes