Emotet — Office (OOXML) / .XLSM malware analysis

Static analysis result for SHA-256 5a83f688dcedc140…

MALICIOUS

Office (OOXML) / .XLSM

104.9 KB Created: 2015-06-05 18:19:34 UTC Authoring application: Microsoft Excel 16.0300
MD5: cc9a77be70e64f2d0102fb4add452483 SHA-1: 35c35e2df6a88a58d88dc10bbda4c7fe06ce8b64 SHA-256: 5a83f688dcedc140bb42b47239e0ef2868e40b1288a1f83f67b3fadf2621a430
250 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The file is an XLSM document containing Excel 4.0 macros, as indicated by multiple critical heuristic firings. These macros utilize dangerous functions like FORMULA to download and execute payloads from the URLs: "http://kambingmedan.net/content/MDgTzDXF/", "http://www.royalerenovation.com/wp-admin/7dLuTyMr1R6V726Wy/", and "http://smallfriendsnantucket.org/backup/01UJlngrKb9Y6eU39hpcOAB/". The ClamAV detection name 'Xls.Downloader.EmotetExcel01220-9935623-0' strongly suggests the Emotet family.

Heuristics 6

  • Excel 4.0 macro sheet (7 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks.
  • Excel 4.0 Auto_Open defined name critical OOXML_XLM_AUTOOPEN_DEFINEDNAME
    Workbook defines _xlnm.Auto_Open or _xlnm.Auto_Close while containing an XLM macro sheet. This is the OOXML/XLSB auto-execution shape for Excel 4.0 macros.
  • Dangerous XLM formula APIs: FORMULA critical OOXML_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet uses formula APIs that call directly into Win32 (=CALL/=EXEC/=REGISTER/=FORMULA). These are the primitives used to download payloads, write files, and start processes from an XLM macro without invoking VBA.
  • ClamAV: Xls.Downloader.EmotetExcel01220-9935623-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.EmotetExcel01220-9935623-0
  • Hidden worksheet (hidden) low OOXML_HIDDEN_SHEET
    Excel workbook contains 9 hidden sheet(s) — hidden sheets are commonly used to conceal macro code, staging data, or intermediate payload construction
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/spreadsheetml/2006/main
    • http://schemas.microsoft.com/office/excel/2006/main
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.microsoft.com/office/spreadsheetml/2009/9/ac
    • http://schemas.microsoft.com/office/spreadsheetml/2014/revision
    • http://schemas.microsoft.com/office/spreadsheetml/2015/revision2
    • http://schemas.microsoft.com/office/spreadsheetml/2016/revision3
    • http://schemas.microsoft.com/office/spreadsheetml/2016/revision6

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.xml
8f782d1c76a62d5afae1d19b857a39346fcdece422c7dee0b3af6070b6023819
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet1.xml 3129 bytes
xlm_sheet_01.xml
621787c533e34737d09b762af3d2a152ca75a80fd7e903515df30e29e068d5ff
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.xml 1277 bytes
xlm_sheet_02.xml
ccaa19e55e8e52cf13f8e65f4c0464016a5bbb2dd78136c4f5a5d422e0821ac7
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet2.xml 1274 bytes
xlm_sheet_03.xml
6dc067852be23d26640c1de355c914c45df59bebe3c1a52dc747e56699894d3e
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet3.xml 1277 bytes
xlm_sheet_04.xml
01e958ffeef22a1437f281219fe244bc530807ab3814f515f63924780414a7b7
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet4.xml 1277 bytes
xlm_sheet_05.xml
ded322adab86158705191658c7b8775245eaa06f0ba30473f122bff4e65e1c33
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet5.xml 1277 bytes
xlm_sheet_06.xml
1d2e15e667a637f45c6776b088de7d4d875cfc86dd067b599b02e759fc459f1f
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet6.xml 1274 bytes