Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 beefe70d04caaff8…

MALICIOUS

Office (OOXML) / .XLSM

441.4 KB Created: 2000-04-13 21:48:14 UTC Authoring application: Microsoft Excel 12.0000
MD5: 802840ef860a5dfb282a1afb9c655320 SHA-1: 4af08627780b9085b915cba34e7a4aded91f6716 SHA-256: beefe70d04caaff897540abbca23c57f43519eef169fe4c71b124ee68488e08f
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1204.002 Malicious File T1105 Ingress Tool Transfer

The sample is an XLSM file containing a Workbook_Open macro. This macro is designed to construct a file path using environment variables and cell values, write obfuscated data to this file, and then execute it using CreateObject. This indicates a downloader or dropper functionality, aiming to execute a second-stage payload. The specific payload and its ultimate destination are not directly discernible from the provided script, leading to an 'unknown family' classification.

Heuristics 5

  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
7f5a9ff6c6c970d1edc26309333ba7fc0d09a84db9b60f4421607ee9372f40d9
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1153 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
9f30857154524b2cdbe920449bdc44636bdb531d5631641eb688d764fd2d77b5
vba-project OOXML VBA project: xl/vbaProject.bin 9216 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.