Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 64e5fbb1bfddba1a…

MALICIOUS

Office (OOXML) / .XLSX

351.2 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: c9583f3fb7fc59a0212e1cfdac8f1f9d SHA-1: ddb32f110b1641101c18c8def3b4cde0540f603e SHA-256: 64e5fbb1bfddba1a05d871a51f6e3fd2590d4d2dcacfc59c6bfbd18212cd7647
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristic firing indicates the presence of Excel 4.0 macros, which are known to be used for executing arbitrary code. While the macro content is truncated, this technique is commonly used to download and execute a second-stage payload. The lack of specific IOCs or identifiable script logic prevents a higher confidence assessment or family attribution.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
3936ee7b0d3a070c59868b2ddff436874d2d62af7b298e8ef41639d101fdeed8
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 360891 bytes