Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 7d24d0eb0e889a3e…

MALICIOUS

Office (OOXML)

246.3 KB Created: 2011-05-17 14:38:26 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2021-05-22
MD5: 5120e4e20e3ad6d2542d58d45ae9cd1d SHA-1: 69fe69779eccc4b37ba333198cc3a79658f08771 SHA-256: 7d24d0eb0e889a3e65eaed7dc2d8a8f89b85de07742c7c23b7750d563310d037
110 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Xls.Downloader.Agent08210-9888570-0. Static analysis revealed an OOXML clickable image form lure pointing to an external hyperlink. This suggests the document is designed to trick users into clicking the link, likely for phishing or to download a secondary payload. No VBA macros were extracted, but the presence of an external link and the nature of the lure strongly indicate a malicious intent.

Heuristics 4

  • ClamAV: Xls.Downloader.Agent08210-9888570-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Agent08210-9888570-0
  • OOXML clickable image phishing/form lure high OOXML_CLICKABLE_IMAGE_FORM_LURE
    Workbook uses a large embedded image as the visible document body and attaches a click-through external hyperlink to that image. The target is a form/collection service or the drawing contains download/view lure text, which is a common credential or document-phishing pattern rather than benign workbook data.
  • External hyperlinks (1) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 1 external hyperlink — clickable URLs are stored as external relationships. First target: http://v7ury17lau0.typeform.com/to/VhlRhyzC
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://v7ury17lau0.typeform.com/to/VhlRhyzC Document hyperlink