Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 a004e6ff0aacdc63…

MALICIOUS

Office (OOXML) / .XLSX

78.4 KB Created: 2020-11-16 05:28:20 UTC Authoring application: Microsoft Excel 16.0300
MD5: 374d3c78b0143ef0177d2ca6b1e80ab1 SHA-1: f979d5dfffa82401c2bdabe9165bbe0a6b6d6a58 SHA-256: a004e6ff0aacdc6381feb62915302d25ecf6bbc6e382fe8a6c788ade2fbaf956
160 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059 Command and Scripting Interpreter

The OOXML file contains VBA macros, specifically a Workbook_Open macro that utilizes the Shell() function. This indicates an attempt to execute arbitrary commands, commonly used to download and run additional malicious content. The presence of VBA macros and the use of Shell() are strong indicators of a downloader or initial access stage.

Heuristics 4

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
edb56740b359681ed8cc7b721fd573f456322bc88430b89aef001b00f957fba3
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1692 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
a45b28b2497d4c733fb2d065425a8c82ec3e79c939428a6cc3be318c55ea3087
vba-project OOXML VBA project: xl/vbaProject.bin 13824 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.