Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 677dbb3d766eb72c…

MALICIOUS

Office (OOXML) / .XLSX

65.9 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 16.0300
MD5: 8a17c1e3019c4ffaad39f98aaf2c3108 SHA-1: e71ecdf6a889dd04e88475d32fa4e1e93ce8cf21 SHA-256: 677dbb3d766eb72cbaf57720f8d7895e2569c209e9b11f820811d8df19c63e7a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are designed to execute arbitrary commands, a common technique for downloading and executing second-stage malware. No specific family could be identified, and no direct IOCs like URLs or hashes were extracted from the macro code itself.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
5d21bcaad710bc6f95e64ef28fa3420445098e57335921f67377254083e9dbf9
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 1100 bytes