Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b122229c18c917bd…

MALICIOUS

Office (OOXML) / .XLSX

162.6 KB Created: 2021-10-14 17:24:36 UTC Authoring application: Microsoft Excel 12.0000
MD5: 8b5146fe001072bc9b54d76e9f9212c4 SHA-1: b795d16f7558ff93e44ab50d65d7f83f604ef8c8 SHA-256: b122229c18c917bd09c8ec02ff56df02a781b588ed98a2ffb0bfcfc8315fcc04
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. While the macro content is heavily obfuscated and truncated, the presence of such macros strongly suggests an intent to download and execute a secondary payload. The specific macro sheet filename, 'xlm_sheet_00.bin', is included as an IOC.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
d70250d650dd67339936d1bbffd9c83fbe9611329bc14404245003943353ab39
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 446763 bytes