Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 9e57c731bd1c3252…

MALICIOUS

Office (OOXML)

8.9 KB Created: 2020-09-22 07:33:06 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2020-10-01
MD5: 235f40284995fc7bf4adfea83fffd2eb SHA-1: cfe34fdcf53283c7925f08b5e72082f1ea1b039b SHA-256: 9e57c731bd1c3252d15b01c3a1b577f103d4a8e9a4d18a6bc45a8ccb7f306372
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.