Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6629f8a218294909…

MALICIOUS

Office (OOXML) / .XLSX

1.28 MB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2023-07-21
MD5: 842d19c29fb93a8b40f3506d4f2847c8 SHA-1: 665279ab4a385a58733f1abe1a105b92603c0215 SHA-256: 6629f8a21829490945d20f755c2d2ee38b94d9d52f050402861c88e9e82c0361
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1204.002 Malicious File T1105 Ingress Tool Transfer

The file contains critical Excel 4.0 macros, including an Auto_Open defined name, indicating immediate execution upon opening. Heuristics also detected WinAPI and download strings within the binary XLM macro sheet, such as 'DownloadToFileA' and 'CreateDirectoryA'. This suggests the macro is designed to download and execute a second-stage payload.

Heuristics 4

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks.
  • Excel 4.0 Auto_Open defined name critical OOXML_XLM_AUTOOPEN_DEFINEDNAME
    Workbook defines _xlnm.Auto_Open or _xlnm.Auto_Close while containing an XLM macro sheet. This is the OOXML/XLSB auto-execution shape for Excel 4.0 macros.
  • Binary XLM macro sheet with WinAPI/download strings critical OOXML_XLM_BINARY_WINAPI_STRINGS
    Excel 4.0 macro sheet is stored as BIFF12/XLSB binary data and contains Win32 download or process-execution API strings such as URLDownloadToFileA, ShellExecuteA, or CreateDirectoryA. These strings are high-signal in XLM macro sheets and catch payload-download macros that XML-formula scanners cannot parse.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in xl/externalLinks/_rels/externalLink1.xml.rels: Данные