Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b3a4ef5a4d3a9f35…

MALICIOUS

Office (OOXML) / .XLSX

320.1 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: e049ebf053a2af12997d932864460793 SHA-1: 0797a29d357b8b2e134b787e4c5ce7dd34ea2e09 SHA-256: b3a4ef5a4d3a9f35b23c6d2d6f8e1f433cc0084ebccf859b02da67ab8592988f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file identified as containing Excel 4.0 macros. This heuristic firing indicates the potential for malicious macro execution. While the macro content is truncated and obfuscated, Excel 4.0 macros are commonly used as a delivery mechanism for second-stage malware. No specific IOCs were extracted.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
ab98bd3b38d9f0c08fa9423d6684d43beea629f8f99684b4f27d4f33508c29b5
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 414684 bytes