Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 7da77c673f1b13fd…

MALICIOUS

Office (OOXML) / .XLSX

116.1 KB Created: 2021-03-29 19:54:41 UTC Authoring application: Microsoft Excel 16.0300
MD5: d98ebc295bbe5c59834f910acf25a29c SHA-1: 948ef8f3fbe70bc3c9a1db8e2e58e5fdf2964278 SHA-256: 7da77c673f1b13fdd3449b4df25537e99cb7ae49f906550683b95517d5681b11
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The critical heuristic firing indicates the presence of an Excel 4.0 macro sheet, which is often used to download and execute malicious payloads. While the macro content is heavily obfuscated and truncated, its structure suggests it is attempting to perform an action, likely downloading a second-stage payload. The file is classified as malicious, and the presence of macros points to a spearphishing attachment delivery method.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
4ba2168210d43affdc2df39a4c02216ffe17c7afee4f75dbc3d4113362e4fe4d
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 96634 bytes