Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 91a9d1482cacbe1a…

MALICIOUS

Office (OOXML) / .XLSX

231.9 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 1e69c532796ae69da06ba992a1b2f03b SHA-1: ea01398474bfd8cced99c66d44545c6f15dfe67d SHA-256: 91a9d1482cacbe1adc5b23f56604b376860c13b69894164a9f79f9292d7f79b1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is heavily truncated and obfuscated, the presence of such macros strongly suggests an intent to download and execute a secondary payload. Without further deobfuscation or network analysis, the specific family and IOCs remain unknown.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
065ead042ccc91188784d46e2bbf892cdb500a02b3d65d2242b891728abee622
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 390542 bytes