Emotet — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 8895c0736eeabc71…

MALICIOUS

Office (OOXML) / .XLSX

262.2 KB Created: 2015-06-05 18:19:34 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2022-03-01
MD5: a1a07f422d760705b40dd6dafeca00f5 SHA-1: c2d5c9ed61aa50f05841aa5ea3ac7df4d1b0b062 SHA-256: 8895c0736eeabc711ad0316c6a42e3f158843cab7275be0f55ef62b9e3d5c57b
120 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

The file is identified as malicious by ClamAV with a specific signature indicating it's an Emotet downloader. Static analysis reveals the presence of Excel 4.0 macros across multiple sheets, which are commonly used to execute malicious code. These macros are likely responsible for downloading and executing a secondary payload, consistent with Emotet's typical behavior.

Heuristics 2

  • Excel 4.0 macro sheet (3 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.
  • ClamAV: Xls.Downloader.Emotet-OOXML_XL-af43432fbcb8603c-9980048-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Emotet-OOXML_XL-af43432fbcb8603c-9980048-0

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
cfdec4781d38aa85d46e4a7bdaa3a4d72c8a73677a644a74bd54ff01f9c4fbcc
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet1.bin 2376 bytes
xlm_sheet_01.bin
f1d88aff69022ae0d15400e52c498eb1e01f1d88da44af58d08b588cf81edeba
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 428 bytes
xlm_sheet_02.bin
8d092ab692439a37110203e92834516fd002e1321c2b7624010918f36f321373
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet2.bin 428 bytes