Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d0612a840b76e5ff…

MALICIOUS

Office (OOXML) / .XLSX

135.8 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: c06c6ee414a336c05312fd01951e41c9 SHA-1: 7da75f9d17bde5b8b54a979d3f6b08fae8fa203e SHA-256: d0612a840b76e5ff85553fb1ba45daa9963cf027f4bbd3c842adb34d630e09c4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is truncated and heavily obfuscated, the presence of such macros strongly suggests an attempt to execute arbitrary code. The primary attack pattern is therefore macro-based execution.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
575a1f7d02ac292925080daaec38e56fe52573ea20071ba738b6a528498ae232
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 621056 bytes