Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 60ca78fbf084dd3d…

MALICIOUS

Office (OOXML) / .XLSX

82.1 KB Created: 2021-03-14 21:03:27 UTC Authoring application: Microsoft Excel 16.0300
MD5: f235e2d66307244100d0f14430c3e501 SHA-1: f513b73dac3f4f08b0016973cca05d34e0e3883e SHA-256: 60ca78fbf084dd3df00eabb0409ab3e9967c2e7d869f0ba6d3fc5cb1f55ab865
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. These macros are known to be used for executing arbitrary commands, often to download and execute further stages of malware. The truncated script content prevents a more detailed analysis of the specific commands being executed.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
caeddfdaad9c006ef2fee8ccd375a4883f2fc8b51ea580570b38f09b3e1b4c71
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 95567 bytes