Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d4094524bb3f72d5…

MALICIOUS

Office (OOXML) / .XLSX

95.0 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 52c1136f8c4c9b1106937abb60e42f92 SHA-1: 229e204531c673d26eb5bd00d0551918b62a46e8 SHA-256: d4094524bb3f72d5ec0ad03ba354ced975b67770db2970ab6cd8fdc7db50674f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. The extracted macro content reveals strings that appear to be paths and filenames, such as 'C:\ProgramData\fnsfunsgfgrgkjfsgnd' and 'rtf'. These are likely used to stage or execute a malicious payload. The macro sheet is truncated, limiting further analysis of the exact execution flow.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
01bd2ad0bb1d300e492859207eba9649087fd4461f5a111a349c1536c6631ed7
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 3870 bytes