Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9fe3300212bcdbba…

MALICIOUS

Office (OOXML) / .XLSX

338.6 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 8698a1c8193ceb1ffc794765ad352071 SHA-1: 6961071be47540d894e3d268e9bc2f8af6fc692e SHA-256: 9fe3300212bcdbba2d67e270808735d17d9311f6b0076edf8b00b354fe5d4f65
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing Excel 4.0 macros. These macros are often used to download and execute additional payloads or perform other malicious actions. No specific IOCs were extracted, and the macro content was truncated, limiting further analysis.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
8d04a116f937c23cf1426e3418dfb82cd203e6c05a7b63bde97e84ccd5d2f3d1
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 611673 bytes