MALICIOUS
180
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
T1203 Exploitation for Client Execution
The sample contains critical heuristic firings indicating Excel 4.0 macros and a reassembled payload. The macros construct commands to execute regsvr32 with specific paths and filenames, suggesting a downloader attempting to launch multiple payloads. The ClamAV detection explicitly names Emotet, a known downloader family.
Heuristics 3
-
Excel 4.0 macro sheet (3 sheet(s)) critical OOXML_XLM_MACROSHEETSpreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.
-
XLM payload reassembled from CHAR()/split formulas critical OOXML_XLM_REASSEMBLED_PAYLOADAn Excel 4.0 macro sheet builds its payload inside the formula token stream by concatenating per-character CHAR() calls and string fragments, so no WinAPI name, shell command, or URL is ever contiguous in the .bin for a literal-bytes scan to find. Reassembling the formulas recovered download/execute API names, LOLBin commands (regsvr32/rundll32/mshta/wmic/powershell), or a payload URL — the de-obfuscated download-and-run kill chain.
-
ClamAV: Xls.Downloader.Emotet-OOXML_XL-af43432fbcb8603c-9980048-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Xls.Downloader.Emotet-OOXML_XL-af43432fbcb8603c-9980048-0
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
emf_00.emfd6bda36da9e27ea2f8c0420fe1f2b87d573e1c9c5708ebdb49479f5292db2dee |
ooxml-emf | OOXML EMF part: xl/media/image2.emf | 6145428 bytes |
xlm_sheet_00.binecf03862c923fefcab2f06822683ed3235adbb58466fc3c02733de48a348c562 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet1.bin | 1074 bytes |
xlm_sheet_01.bin5a16025ed94a3e1a4ed9f440f85989f9326278b8a9028170d1da2bb8493c3c56 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet2.bin | 2703 bytes |
xlm_sheet_02.binebe8249fb8fbfb9b3fd1240f9e8c37aaaebc007f935e60083156978492cc33f0 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet3.bin | 1122 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.