Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 adf5f04b4272ae07…

MALICIOUS

Office (OOXML) / .XLSX

111.9 KB Created: 2021-03-29 19:56:22 UTC Authoring application: Microsoft Excel 16.0300
MD5: eb71698b6a9b17ab4ed930293412d710 SHA-1: a809bc2d23950803747a0929c8f8de0f1b33f36e SHA-256: adf5f04b4272ae07a4aa7bfe13fbc4c0d9aac805795f4661d453af5ba740ed89
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is truncated and heavily obfuscated, the structure suggests it is designed to download and execute a second-stage payload. The specific commands and their order are not fully discernible due to truncation, preventing a more precise analysis of the execution flow or specific IOCs.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
18c12248c131e85846e885beace66aed801f124d7142b0ed6e73a6e8bac34730
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 91649 bytes