Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6258c48e2ba9da68…

MALICIOUS

Office (OOXML) / .XLSX

311.7 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 57fa561ecb1002468fab2c804e9dbe56 SHA-1: 0418d558877be17e90302e505a403023a8e925e7 SHA-256: 6258c48e2ba9da68f46662e02b7d095f2100cd62466ddb562135ae87151c4fd3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are often used to download and execute malicious payloads. While the specific commands within the macro sheet are truncated and obfuscated, the presence of XLM macros strongly suggests an attempt to compromise the user's system, likely delivered via spearphishing.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
56fc1739a07e9fdd0c1c509043016fefb8dc00d93b4ee20ea9e16907f69e9e1b
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 277817 bytes