Ldridex — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a949580bb69cb570…

MALICIOUS

Office (OOXML) / .XLSX

31.5 KB Created: 2020-09-08 11:59:25 UTC Authoring application: Microsoft Excel 16.0300
MD5: 34a5d39dc954b70d0f28a5528ac641c4 SHA-1: d62aa48b527f116513b2cee31ccf9786620f244d SHA-256: a949580bb69cb570559e2ff524747e0fced10ad027881ec396c893778061a0d3
140 Risk Score

Malware Insights

Ldridex · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.005 Visual Basic

The file is identified as malicious by ClamAV with the signature Xls.Malware.Ldridex-9768648-0, indicating it belongs to the Ldridex family. The presence of VBA macros within the OOXML structure, combined with the obfuscated document body, strongly suggests a macro-based attack designed to trick the user into enabling content. This macro functionality is likely used to download and execute a secondary payload, a common Ldridex tactic.

Heuristics 3

  • ClamAV: Xls.Malware.Ldridex-9768648-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Ldridex-9768648-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
8873c752da58b642408d52bcdd8b5a83063f98901ac76d8fa233f96313bd6d24
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 2566 bytes
vbaProject_00.bin
c5ebf972fd39e09e72e4759f54c6814c93c3bd918e88863bac603f37af356b09
vba-project OOXML VBA project: xl/vbaProject.bin 20992 bytes
Detection
ClamAV: Xls.Malware.Ldridex-9768648-0
Obfuscation or payload: unlikely
emf_00.emf
b5bade02daded562effbe609b7a4c7c01c1ee2a1f26708539a8df738ed841fce
ooxml-emf OOXML EMF part: xl/media/image1.emf 3432 bytes