Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 81b846765978f2ee…

MALICIOUS

Office (OOXML) / .XLSX

197.2 KB Created: 2021-02-27 09:36:14 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2026-05-21
MD5: f56b13a4531308320270298e8c2ea192 SHA-1: 25c0468d4ba09f05c0c75c5e0ac74583f3fd0ba2 SHA-256: 81b846765978f2eed8e4e9ef5e6187a551694a51e5ffeb19d77b03f8a6ccc523
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. These macros are designed to execute arbitrary commands, likely to download and run a secondary payload. The specific macro sheet filename is provided as an IOC.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 8324 bytes
SHA-256: ac32c00d3deeda42acbc60e26e7a5a37a1660296bc4aeb849340da9f360aaa01
Preview script
First 1,000 lines of the extracted script
�  �  �   @      ��������    �      �           �  %      ��                  & �  �     �       @   d           � $    �                   ��      �?  �  �  %      ��    & �  ����  ,     �  <         ��        <     �?  $	        �  �  %      ��    &           ,                              %      ��    &           ,                 �            %   I!  @  #�   #!     @  #    #,    #�    #x    #�    #�      @  #    #�    #�    #     #�      @  #    #/    #:    #�      @  #    #     #B    #     #7    #8    #6    #�    #�    #     #d    #�    #%    #7    #n    #]    #9    #�    #     #$    #     #�    #k    #     #L    #<    #E    #w          %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &   
       ,                          !   %      ��    &           ,                          "   %      ��    &           ,                 k           X   I1  @  #�   #E    #�    #     #x    #      @  #I     I   @  #�   #&    #     #h     @       %      ��    &           ,                          #   %      ��    &           ,                          $   %      ��    &           ,                              %      ��    &           ,                 �            %   I!  @  #�   #!     @  #    #,    #�    #x    #�    #�      @  #    #�    #�    #     #�      @  #    #/    #:    #�      @  #    #     #B    #     #7    #8    #6    #�    #�    #     #d    #�    #%    #7    #n    #]    #9    #�    #     #$    #     #�    #k    #     #L    #<    #E    #w          %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                              %      ��    &           ,                          !   %      ��    &           ,                          "   %      ��    &   "       ,                 k           X   I1  @  #�   #E    #�    #     #x    #      @  #I     I   @  #�   #&    #     #h     @       %      ��    &   $       ,                          #   %      ��    &   &       ,                          $   %      ��    &   (       ,                          %   %      ��    &   *       ,                 �            �   I�  @  #�    @  #-   #'    #�    #l    #�      @  #r   #z    #       @  #J   #>    #�      @  #A   #�    #U    #�    #f      @  #G   #
    #�    #{    #�    #U    #X    #	    #�    #t    #K    #g    #q    #�    #N    #+          %      ��    &   ,       ,                          &   %      ��    &   .       ,                          '   %      ��    &   0       ,                          (   %      ��    &   2       ,                          )   %      ��    &   4       ,                          *   %      ��    &   6       ,                 e           R   I1  @  #�   #*    #=    #�    #l    #s     @  #I     I   @  #�   #�    #h     @       %      ��    &   8       ,                          +   %      ��    &   :       ,                          ,   %      ��    &   <       ,                          %   %      ��    &   >       ,                 �            �   I�  @  #�    @  #-   #'    #�    #l    #�      @  #r   #z    #       @  #J   #>    #�      @  #A   #�    #U    #�    #f      @  #G   #
    #�    #{    #�    #U    #X    #	    #�    #t    #K    #g    #q    #�    #N    #+          %      ��    &   @       ,                          &   %      ��    &   B       ,                          '   %      ��    &   D       ,                          (   %      ��    &   F       ,                          )   %      ��    &   H       ,                          *   %      ��    &   J       ,                 e           R   I1  @  #�   #*    #=    #�    #l    #s     @  #I     I   @  #�   #�    #h     @       %      ��    &   L       ,                          +   %      ��    &   N       ,                          ,   %      ��    &   P       ,                 �            �   I!  @  #W   #p    #S    #>    #Y     Ii  @  #[   #P     @  #�   #Q    #M    #�    #\    #�      @  #M   #�      @  #V   #R 
... (truncated)