Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 c9fa7a8c2ac44adf…

MALICIOUS

Office (OOXML) / .XLSX

104.5 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 740f8fad4409804908f463b78947badb SHA-1: 8ce79d91eded6368f11e8a4e47cf9c7feed9f3ca SHA-256: c9fa7a8c2ac44adf4023f01d04b3aca400fa7780c3767c70adb432fb1445c2ac
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within an XLSX file. While the macro content is heavily truncated and obfuscated, the presence of such macros is a strong indicator of malicious intent, often used for downloading and executing further stages of an attack. The file is classified as malicious with a risk score of 60.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
a954e520de0d5e42a64e8717f235b0a587c459496d542115f3dbfd591090addf
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 4105 bytes