Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 ac499be152fd3bf1…

MALICIOUS

Office (OOXML) / .XLSX

98.0 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 16.0300
MD5: f53fdbf650f8079b40e9ddb2c7fe41c9 SHA-1: 062b26e37cd5eb8cd70b11bd89f1908268880d99 SHA-256: ac499be152fd3bf1a958d67233e5bf1484360892d8c6040e0941748735939f2a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macro sheets within the OOXML file. While the macro content is heavily obfuscated and truncated, the presence of these macro sheets strongly suggests an attempt to execute arbitrary commands upon opening the document. This is a common technique for initial payload delivery.

Heuristics 1

  • Excel 4.0 macro sheet (3 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
emf_00.emf
ab58818ae1864807b22f8a58a75f7fa8703ecb19a2352bdb47469f366b868e59
ooxml-emf OOXML EMF part: xl/media/image2.emf 1108 bytes
xlm_sheet_00.bin
7ba8c7dae215c3d653270796d8570b3810c64068590cf64325562d684e829370
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 1340 bytes
xlm_sheet_01.bin
cb1f1a0b36df7c5b1ecd6c45b74a2d4711b2827f0ee30f82c9df4f6bc63e617f
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet2.bin 1509 bytes
xlm_sheet_02.bin
ab6060707b634032a9e28cdf4014bbeee5441e8ba06b1724bdb26e4c68089d59
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet3.bin 1296 bytes