Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 9dc50ad27411c1bb…

MALICIOUS

Office (OLE) / .XLSX

31.0 KB Created: 2021-01-25 13:48:31 Authoring application: Microsoft Excel
MD5: 2c361eb160f7946680e065ed1e7a67b0 SHA-1: 602fae2ca971691da5f99e6ba08be48b86ca9457 SHA-256: 9dc50ad27411c1bbacd881a936e0ad97e6370979fdd3897d8145852d0b3ad2e6
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.005 Visual Basic T1059.001 PowerShell

The sample is an Excel file containing Excel 4.0 macros, specifically an Auto_Open macro. The document body contains a lure instructing the user to enable editing and content, which is a common tactic for macro-based malware. The presence of the Auto_Open macro and the lure strongly suggests the intent is to execute malicious code upon opening the document. No specific family could be identified, but the technique is consistent with macro-based downloaders.

Heuristics 4

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
088fd6b0593805a3d5f798ca3f32e4dba54d3eb092917819d39f97bd18a7aac6
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 3573 bytes