Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b7aa9adcd202fbca…

MALICIOUS

Office (OOXML) / .XLSX

85.7 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 3ed1d1234e411d6eb982d51aaa2aa002 SHA-1: cfe8f346a41b15100bb8afc6279261b7b7ee4f5b SHA-256: b7aa9adcd202fbca83414dfbefe93b73723b07e7aa245c742a55ea836e8d5aa2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of an Excel 4.0 macro sheet. Analysis of the macro sheet reveals it constructs and executes a command to write a file to 'C:\ProgramData\fnsfunsgfgrgnkjfsgnd'. This suggests a downloader or dropper functionality, aiming to place a malicious payload in a common location for executables.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
f5543c91f65f5a38dffb3674ee858e071d6c6977655cff67566007c7dcdebb94
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4284 bytes