Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6309abba3507ef95…

MALICIOUS

Office (OOXML) / .XLSX

81.3 KB Created: 2021-02-26 07:53:41 UTC Authoring application: Microsoft Excel 16.0300
MD5: aa9d79444413e56b31949d8aed4f5b5d SHA-1: 29b8d7afcc8ff5a8708ecf0650c165a0a1fbea73 SHA-256: 6309abba3507ef959aa76a4ef9abd45dde4a538b2fa2a57036959e793b2c33b9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are capable of executing arbitrary commands, which is a common technique for downloading and executing further malicious stages. The truncated script content prevents a more detailed analysis of the specific commands or URLs used.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
463877f352153dd4c56c7cc0d49290efde303b22141cb421b12f2495de60e66a
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4569 bytes