Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9178c52f3b0fd561…

MALICIOUS

Office (OOXML) / .XLSX

63.6 KB Created: 2021-03-14 20:07:08 UTC Authoring application: Microsoft Excel 16.0300
MD5: 8a45db195455249ec54f996d552f93bd SHA-1: f66dd2cfae0f4447e3dc26745eb3f330a07c4184 SHA-256: 9178c52f3b0fd561a2dc1ed1f075dc647dbd8aa12b89355b159a16706f383b18
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. While the macro content is heavily truncated and obfuscated, the presence of such macros strongly suggests a malicious intent, likely to download and execute a second-stage payload. The specific macro sheet filename is included as an IOC.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
f42b99f980048828f35f257c1a9803b6fb8cffad4abcb712ecf7dc8a682ba589
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 92580 bytes