Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 a2cd0c638ee2de3d…

MALICIOUS

Office (OOXML) / .XLSX

132.4 KB Created: 2021-09-20 10:27:09 UTC Authoring application: Microsoft Excel 12.0000
MD5: 0ff26db932ff7a0dfdd87c56feb8df41 SHA-1: 584677f0b10e9137bf94ab391bfa4fb893124fc2 SHA-256: a2cd0c638ee2de3d2420aa03962db94a1b72a6631d1c8cea9bc69c4992bb45ef
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

The file is identified as malicious by ClamAV and contains Excel 4.0 macros. The macro sheet contains obfuscated commands that likely attempt to download and execute a second-stage payload from a URL embedded within the macro code. The presence of the ClamAV detection name 'Xls.Downloader.Trojan' further supports this assessment.

Heuristics 2

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.
  • ClamAV: Xls.Downloader.Trojan-a0425f7f2000faff-a0425f7f2000faff-9950268-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Trojan-a0425f7f2000faff-a0425f7f2000faff-9950268-0

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
6f6bbaa5310c80b923f284213a95bea20783e01031e041d0627de1bab8f92f17
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 877 bytes