Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6902a1d34acdc62f…

MALICIOUS

Office (OOXML) / .XLSX

66.6 KB Created: 2021-03-15 18:25:48 UTC Authoring application: Microsoft Excel 16.0300
MD5: d73a7db9f19b66c09e831dc8b9de6e8a SHA-1: 74532462f7debc64ec2bd9da5dfee6514db60309 SHA-256: 6902a1d34acdc62f6f9b0722852c9fd4a0ec8d05d9ccd936257d7a0224e7c3e4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are known to be used for executing arbitrary commands, often to download and execute further malicious stages. The truncated script content prevents a more detailed analysis of the specific commands or URLs used.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
e00591cea21cf472c74e2c4b9706ff8b685d544de892ddf32acfd365dfb1f001
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 90467 bytes