Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 cc132ea4bd2036d6…

MALICIOUS

Office (OOXML) / .XLSX

1.21 MB Created: 2015-06-05 18:19:34 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2022-03-23
MD5: afb13f774296196e12a7a7d6b18dbe74 SHA-1: 55ad2348425a09358f13b8be03ee85489711a636 SHA-256: cc132ea4bd2036d64ec24f29d5d368fd3f1706584572a08698414f5fd580f4c0
122 Risk Score

Malware Insights

MITRE ATT&CK
T1059 Command and Scripting Interpreter

The file is an XLSX document containing multiple Excel 4.0 macro sheets. This indicates a likely attempt to execute arbitrary commands or download further payloads upon opening. The presence of these macro sheets is a strong indicator of malicious intent, commonly used for initial access or payload delivery.

Heuristics 3

  • Excel 4.0 macro sheet (12 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.
  • XLSB international XLM macro sheet hidden in .xlsx critical OOXML_XLSB_INTL_MACROSHEET_IN_XLSX
    OOXML package is named .xlsx but contains XLSB workbook parts and an international Excel 4.0 macro sheet. This hides XLM macro execution from scanners that trust the extension or only inspect XML worksheet parts. The technique is macro execution, not a document-parser CVE.
  • Large OOXML part skipped info SCAN_INCOMPLETE
    One or more high-value OOXML parts exceeded the scanner's per-entry size cap and may not have been fully inspected.