Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 aeacfc5c498bad54…

MALICIOUS

Office (OOXML) / .XLSX

373.2 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 557e74c327db2b0d810b945283983c53 SHA-1: b198b388d03be5a56143b6d927e5193307f5fff8 SHA-256: aeacfc5c498bad54ee45c1fe5686b598f11f94b8cf77c86cf8b49525a211efc9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of an Excel 4.0 macro sheet. While the macro content is heavily truncated and obfuscated, the presence of such macros is a strong indicator of malicious intent, typically used to download and execute further stages. The file's metadata shows it was created by Microsoft Excel.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
dd261d4fd5dbae876edc1f256c4c5c35e99541baa7aa8d2d4a7d135074826b73
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 633313 bytes