Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 c5f471cbef8a985a…

MALICIOUS

Office (OOXML) / .XLSX

355.2 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: a74fc66d1394d5338c30a3a8491c0ad8 SHA-1: ef58b332dee557c17827637ddd5cd68d5a046497 SHA-256: c5f471cbef8a985a1c39d475bdc2e11b3f4360c939b7aa7588136c76a4d3ed3b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing an Excel 4.0 macro sheet, indicated by the OOXML_XLM_MACROSHEET heuristic. This type of macro sheet is known to be used for executing arbitrary commands, often to download and run further malicious payloads. The macro content itself is heavily truncated and obfuscated, preventing a detailed analysis of its specific actions or reconstruction of any URLs or commands.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
d0b1fa7640a0d71ca8405baf5f586adc4a6bc8cd24b7e76c3f56d15811a9df48
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 218201 bytes