Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 9dca8263e663b03a…

MALICIOUS

Office (OOXML)

25.1 KB Created: 2021-02-15 01:06:36 UTC Authoring application: Microsoft Excel 15.0300 First seen: 2021-04-01
MD5: 2765bdaf439afcfb167217863efebdae SHA-1: 1f0547fee4e47172fd118fdd98b95b2862affc1e SHA-256: 9dca8263e663b03a98368d6872d9dd75fac1c9b6b970bb9e3c5b696a345d10dc
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.