Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b8962c1c7c43d1f6…

MALICIOUS

Office (OOXML) / .XLSX

108.3 KB Created: 2021-03-29 19:56:22 UTC Authoring application: Microsoft Excel 16.0300
MD5: 76ad56babfdaa02f3a8841bbcf2ded49 SHA-1: e6b20bb9026eade7e08fc5fdad0f201aecfb905c SHA-256: b8962c1c7c43d1f6d4751c07f60719aa30f4bd28c04a8ea5f5b5a37e1113f21d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file identified as containing Excel 4.0 macros. The macro sheet appears to be heavily obfuscated and truncated, making it difficult to determine the exact execution flow or payload. However, the presence of Excel 4.0 macros strongly suggests an intent to download and execute a secondary payload, a common technique for initial access.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
74f2d7197cba7eddbaa39bee05d6d3c8dc72963e96eda8c915d6489dcf8b097e
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 91649 bytes