Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 bb62cccf107b94ab…

MALICIOUS

Office (OOXML) / .XLSX

119.1 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: b9ae09a6c653363b2111973892d91f59 SHA-1: 7efd0a827e8ff665676fad64a446e91fef09e2a9 SHA-256: bb62cccf107b94abb916f1568a0518324199746042d4b42bd6df35d6e5f21e7d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing a macro sheet, identified by the OOXML_XLM_MACROSHEET heuristic. The extracted macro content is heavily obfuscated and truncated, making it difficult to determine the exact payload. However, the presence of Excel 4.0 macros strongly suggests an intent to execute arbitrary commands upon opening the document.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
094cbef56b7c46ad251ed8e7252c9df53435b0342164ca867b1281c5caece746
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 3863 bytes