Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 6aaeceb9d789e2e5…

MALICIOUS

Office (OOXML) / .XLSX

81.3 KB Created: 2021-02-26 07:53:41 UTC Authoring application: Microsoft Excel 16.0300
MD5: 6caf312bdfc3b31d0f8e9d23c308081b SHA-1: 26e46601c3534628a2f30a7580b1979fc51f48cd SHA-256: 6aaeceb9d789e2e5d0d3940b75b73549efce0e2eb839bfe47cba51eb1870eb68
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is an Excel spreadsheet containing Excel 4.0 macros, a known technique for executing malicious code. The heuristic firing confirms the presence of these macros, which are often used to download and execute further stages of malware. No specific IOCs were extracted from the macro content itself, but the technique strongly suggests an initial access vector via spearphishing.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
b1d371481944a0263e97095b2c5f1952d812ed2f5dc6848568fc69f349b92eb4
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4569 bytes