Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 c4d78b3059d228b9…

MALICIOUS

Office (OOXML)

83.9 KB Created: 2021-01-31 17:47:11 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2021-02-18
MD5: f81a8b223287fab66b71b7dc6436081a SHA-1: aeb8a82c28fc6033782aa1f1073f49dc69123c54 SHA-256: c4d78b3059d228b9255b76e7cd8d9b2d2545c76d29f68728c2ca530011c0f0e1
60 Risk Score

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 2633 bytes
SHA-256: f3b25da59d55ffd67c915c108057098cda01a0a2ca11e98bf2c3b5abeacfb221
Preview script
First 1,000 lines of the extracted script
�  �  �   @      ��������    �                  �  %      ��                  & �  �             @   d           � $                                    �  �  %      ��    & �  ����  ,     �  <         �%        <     �?  $	        �  �  %      ��    &           ,                	,              Y@       d      d     B       %      ��    &           ,                
                $     �B  �    %      ��    &           ,                	'             Ђ@  
       �  � B       %      ��    &           ,                	,              i@       �      �     B       %      ��    &           ,                          ?   %      ��    &           ,                	E              �?  +   Z       �:       �:      
�:       �   B �     %      ��    &           ,                          @   %      ��    &           ,                	,              y@       �      �     B       %      ��    &           ,                
:           '       AJ  @     0 0 : 0 0 : 0 3  @   B ��    %      ��    &   	       ,                          A   %      ��    &   
       ,                	T           �����  :   Z       �:       �:      
�   :       �:      	�      B �     %      ��    &           ,                          B   %      ��    &           ,                	,             Ȅ@       �      �     B       %      ��    &   
       ,                
                $     �B  �    %      ��    &           ,                	'             _�@  
    �  �  G B       %      ��    &           ,                
:           '       AJ  @     0 0 : 0 0 : 0 5  @   B ��    %      ��    &           ,                	0             8�@       �      �         B       %      ��    &           ,                
                $     �B  �    %      ��    &           ,                	-             ��@          b  �  �    B       %      ��    &           ,                          C   %      ��    &           ,                	0             �x@       �      �         B       %      ��    &           ,                	a              E@  G   Z       �:       �:       �   :  
    �:       � @  :       �      B	�     %      ��    &           ,                          D   %      ��    &           ,                          E   %      ��    &           ,                
                B 6     �  � � ��                                                                  @   �K�XR��o;D���g�	� ! ��VG# �H6�x� T�4-f�
1  �Bĸ�F[ c ���|e Xjo�    .��R �49�)k˛�>�    S H A - 5 1 2 � B                                                                  �  ��� 0ffffff�?ffffff�?      �?      �?333333�?333333�?%      ��                  & �