MALICIOUS
250
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 Command and Scripting Interpreter: PowerShell
T1204.002 User Execution: Malicious File
T1105 Ingress Tool Transfer
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
T1218.011 System Binary Proxy Execution: Rundll32
T1129 나s a single JSON object only. No prose, no markdown, no code fences. The object must have exactly these keys: { "attack_
T1027 Obfuscation
The sample uses Excel 4.0 macros (XLM) to download a payload from one of several hardcoded URLs, including 'http://new.amazonbroker.com/MsQseVusvE9YRl/DpLceIxuG3t0ALQ/', 'http://new.hsnbroker.com/7/Pggi69PuxiPPLgVd/', and 'http://new.qvcbroker.com/3/OW5E1T2x/'. The script then saves the payload as 'C:\Windows\bestb.ocx' and executes it using 'rundll32.exe' via the 'DllRegisterServer' export. This pattern is highly characteristic of Emotet, which is further supported by a ClamAV detection for Xls.Downloader.Emotet.
Heuristics 6
-
Excel 4.0 macro sheet (7 sheet(s)) critical OOXML_XLM_MACROSHEETSpreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks.
-
Excel 4.0 Auto_Open defined name critical OOXML_XLM_AUTOOPEN_DEFINEDNAMEWorkbook defines _xlnm.Auto_Open or _xlnm.Auto_Close while containing an XLM macro sheet. This is the OOXML/XLSB auto-execution shape for Excel 4.0 macros.
-
Dangerous XLM formula APIs: FORMULA critical OOXML_XLM_DANGEROUS_FNExcel 4.0 macro sheet uses formula APIs that call directly into Win32 (=CALL/=EXEC/=REGISTER/=FORMULA). These are the primitives used to download payloads, write files, and start processes from an XLM macro without invoking VBA.
-
ClamAV: Xls.Downloader.EmotetExcel122100-9913103-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Xls.Downloader.EmotetExcel122100-9913103-0
-
Hidden worksheet (hidden) low OOXML_HIDDEN_SHEETExcel workbook contains 11 hidden sheet(s) — hidden sheets are commonly used to conceal macro code, staging data, or intermediate payload construction
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/spreadsheetml/2006/main
- http://schemas.microsoft.com/office/excel/2006/main
- http://schemas.openxmlformats.org/officeDocument/2006/relationships
- http://schemas.openxmlformats.org/markup-compatibility/2006
- http://schemas.microsoft.com/office/spreadsheetml/2009/9/ac
- http://schemas.microsoft.com/office/spreadsheetml/2014/revision
- http://schemas.microsoft.com/office/spreadsheetml/2015/revision2
- http://schemas.microsoft.com/office/spreadsheetml/2016/revision3
- http://schemas.microsoft.com/office/spreadsheetml/2016/revision6
Extracted artifacts 7
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
xlm_sheet_00.xmlf51df967c9a79675ef430ab610a20d6a4c94bb90710f2dafb84224b8e8da9eac |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/intlsheet1.xml | 3032 bytes |
xlm_sheet_01.xml1d840e58b613d5aaf0c1584ddad983c459013d0020172bf8c42753a3ca5c10ce |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet1.xml | 1367 bytes |
xlm_sheet_02.xml9530473eeb7ce4531ba6f2fb74f3f8b15d5970a3f986b2de8204ee4e69d17bcb |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet2.xml | 1367 bytes |
xlm_sheet_03.xml5298b05c0f3d1a953d0ede7427cc089251a7652227e518fae265a133c04b11f5 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet3.xml | 1364 bytes |
xlm_sheet_04.xml5f53215a8438bb7fe5a809106144bae36a7af9a316481ee676680c60ac4893c6 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet4.xml | 1364 bytes |
xlm_sheet_05.xml466ccb4b7c309940a771659ee00d4db755bdde38abf836c5ee99a946f296d356 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet5.xml | 1367 bytes |
xlm_sheet_06.xml85d88333fb0430df1cb4b286e0f1d952b0e36ae77f3e113b23aadd6e029134fc |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet6.xml | 1366 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.