Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9a0cc08c8a0365eb…

MALICIOUS

Office (OOXML) / .XLSX

118.7 KB Created: 2021-03-29 19:54:15 UTC Authoring application: Microsoft Excel 16.0300
MD5: a44bcb5dc789b24bbf75faf97dada5c0 SHA-1: f1e804a94a1bdf5906bf6336e2ebf894398e88a6 SHA-256: 9a0cc08c8a0365eb34db530ee6a8d371cfe29a7cd01c4526962ab3b05130d5a7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. While the macro content is truncated, the presence of such macros strongly suggests an attempt to execute arbitrary commands upon opening the document. This is a common technique for initial payload delivery.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
d949a8b7ffa97589188bab8170d521758076d1b4c068e080055a6adbc7dea520
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 98782 bytes