Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 62bdce3b73efcaec…

MALICIOUS

Office (OOXML) / .XLSX

148.6 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: e11c342197b9a7b44373a560cfc24445 SHA-1: 544d099372a6a0e3d97d1ba42ec51644c9ff935c SHA-256: 62bdce3b73efcaec16736e09565aee8619db940ba1a733c814c4a8a8e3b9fbd1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing Excel 4.0 macros, which are known to be used for malicious purposes. The heuristic firing indicates the presence of these macros, suggesting an attempt to execute arbitrary commands. The macros themselves are heavily obfuscated and truncated, preventing a detailed analysis of their specific actions, but the general intent is likely to download and execute a secondary payload.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
dfd1e47775605544735e6db09837c1609320e78cfeaa01d762863f875e233e78
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4362 bytes