Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 66b66fcd3ebb2a51…

MALICIOUS

Office (OOXML) / .XLSX

1.55 MB Created: 2015-06-05 18:19:34 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2024-05-22
MD5: a63485b442a8206671ebc6a88be95235 SHA-1: 6527d42ec4b02786a32169dab0389a4774ad19b8 SHA-256: 66b66fcd3ebb2a51ef73fae0049f5029215ce432d3647bc54ee5245912a6c955
110 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.005 Visual Basic

The file is an XLSX document containing VBA macros, specifically a Workbook_Open macro, which is a common technique for initial execution. The macro manipulates data within sheets named 'Паспорт' and 'подписанты' by copying and pasting values, suggesting an attempt to prepare or exfiltrate data. While the provided URL is benign, the presence of active macros and data manipulation within a malicious document indicates a likely attempt to compromise the user or system.

Heuristics 5

  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • External relationship high OOXML_EXTERNAL_REL
    External target in xl/externalLinks/_rels/externalLink1.bin.rels: file:///C:\SID\SID Надстройка.xlam
  • VBA project inside OOXML medium OOXML_VBA
    Document contains a VBA project — VBA macros present
  • External hyperlinks (1) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 1 external hyperlink — clickable URLs are stored as external relationships. First target: file:///Y:\Downloads\Content.Outlook\Content.Outlook\Content.Outlook\Content.Outlook\Новая папка\[Центр СИД.xlsm
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://youtu.be/dSwHRgYBlVw

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
666a03710925074d26c002a3d3693f41bcdec7a9a2b73c3c5f87fa6ec5265291
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 5091 bytes
vbaProject_00.bin
8d49c645b83de67cc696ab234b8b57ed32b1659ac0fc902b22b35f8e9f3f5837
vba-project OOXML VBA project: xl/vbaProject.bin 44032 bytes