Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 758d83ffe8635ed0…

MALICIOUS

Office (OOXML) / .XLSX

81.3 KB Created: 2021-02-26 07:53:41 UTC Authoring application: Microsoft Excel 16.0300
MD5: 787f5dffa789139f88c27016cc200d71 SHA-1: 60ede54417fcfd6b87c85071a5f261c9d98768a2 SHA-256: 758d83ffe8635ed095eb2d83b760309493d307ac84eebf11cc2317a23e14a8c3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel 4.0 macro sheet, indicated by the OOXML_XLM_MACROSHEET heuristic. Excel 4.0 macros are capable of executing arbitrary commands, which is a common technique for initial payload delivery. The macro content itself was truncated, preventing a more detailed analysis of its specific actions or IOCs.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
97c1eb0997eab8f3726e0c07536f4ea15d780e5a916779057d773a30b6ffd256
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4569 bytes
Preview script
First 1,000 lines of the extracted script
�  �  �   @      ��������    �      Q           �  %      ��                  & �  �     ]       @   d           � $    m               m   m           �  �  %      ��    & �  ����  ,     �  <         I)        <     �?  $	        �  �  %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &   
       ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &   !       ,                              %      ��    &   #       ,                              %      ��    &   %       ,                              %      ��    &   '       ,                              %      ��    &   )       ,                              %      ��    &   *       ,                              %      ��    &   +       ,                              %      ��    &   ,       ,                              %      ��    &   -       ,                              %      ��    &   .       ,                 =           *   I   @  #/   #      I   @  #.   #%     @       %      ��    &   /       ,                              %      ��    &   0       ,                 W           D    @  C     I   @  #.   #
    #D    #)     @   I   @  #1   #*     @       %      ��    &   1       ,                              %      ��    &   2       ,                              %      ��    &   3       ,                          	   %      ��    &   4       ,                              %      ��    &   5       ,                          
   %      ��    &   6       ,                              %      ��    &   7       ,                 I           6   I   @  #<   #     #$    #-     I   @  #3   #      @       %      ��    &   8       ,                              %      ��    &   9       ,                              %      ��    &   :       ,                              %      ��    &   ;       ,                              %      ��    &   <       ,                          
   %      ��    &   =       ,                              %      ��    &   >       ,                 O           <   I!  @  #C   #     #     #'    #0     I   @  #9   #"     @       %      ��    &   ?       ,                              %      ��    &   @       ,                              %      ��    &   A       ,                              %      ��    &   B       ,                              %      ��    &   C       ,                              %      ��    &   D       ,                
>           +   Z  #    �:  %    �:  '    �:       �   B �     %      ��    &   E       ,                              %      ��    &   F       ,                
:           '       AJ  @     0 0 : 0 0 : 0 1  @   B ��    %      ��    &   G       ,                              %      ��    &   H       ,                
D           1   Z  3    �Z  6    �Z  8    �   B A Q L      	 B �     %      ��    &   I       ,                 7           $   #       :  B   
�:       �      B �     %      ��    &   J       ,                              %      ��    &   K       ,                
:           '       AJ  @     0 0 : 0 0 : 0 5  @   B ��    %      ��    &   L       ,                              %      ��    &   M       ,                
V           C   Z       �:  !    �:  $    �   :      	�:       �:  &   	�      B	�     %      ��    &   N       ,                              %      ��    &   O       ,                  
... (truncated)