Malicious Office (OOXML) / .XLSM — malware analysis report

Static analysis result for SHA-256 d18c514f56454991…

MALICIOUS

Office (OOXML) / .XLSM

438.2 KB Created: 2021-07-28 10:37:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 0849c09e632bce7e4ae4e59745c1879c SHA-1: f555b7c9d16bb6376cecfdbde42996093ae7c46c SHA-256: d18c514f56454991d876242e6a626701df15a9c8b6f577685e94d536233d37c1
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

This XLSM file contains a Workbook_Open macro that is designed to execute a payload. The macro constructs a command using environment variables and cell values, then uses CreateObject to execute it. The specific payload and its ultimate destination are obfuscated within the macro's logic, making it difficult to determine the exact nature of the second-stage execution without further dynamic analysis. However, the intent is clearly to download and execute a malicious payload.

Heuristics 5

  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
7c525bf9e2f002aec2e97f0f7c440c238c5403c2b4d98d1a2505fbef8d7715c5
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 1118 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
967350f6a5fb79f9cc5c27763c101adc20a71c69d0c7df2257b948d9518683b5
vba-project OOXML VBA project: xl/vbaProject.bin 9216 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.