Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 89585b9c9e84af53…

MALICIOUS

Office (OOXML) / .XLSX

136.8 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 0e79287419f57e37c6c3751ae928d148 SHA-1: 75ba6cd43bc719854a00e1bef285c00b4bd1396d SHA-256: 89585b9c9e84af5385d52f87b0b8b946f7ac73e6eead2f1cbd4c8fee351c16cc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing Excel 4.0 macros. The heuristic firing indicates the presence of these macros, which are often used to execute arbitrary commands or download additional payloads. The macro content is heavily truncated and obfuscated, preventing a detailed analysis of its specific actions or IOCs. Therefore, the exact attack pattern and family remain unclear.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
b69e2f6d3c5517cbe57ff7c2c6b3a4dab875a46a9195b2e1691399f0fdf10a23
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 630363 bytes