Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d6dcc0a6e5a7a398…

MALICIOUS

Office (OOXML) / .XLSX

141.4 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: f44ea0b7e1beca02370c8aa2d20000f6 SHA-1: e22c0471b5ca2e43f3733524dfa384dad35160fa SHA-256: d6dcc0a6e5a7a3985fab975e4da5a1cc4ca904f68556dd98b062430d53426bea
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing Excel 4.0 macros, which are known to be used for malicious purposes. The macros are heavily obfuscated and truncated, making it impossible to determine their exact function or reconstruct any specific IOCs. However, the presence of these macros strongly suggests an attempt to execute arbitrary code.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
127bd5bab990e5fa20df136ccaf1b0b6beca831a1752f53a95610de02059820c
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 673776 bytes