Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d9fe9c268dabc421…

MALICIOUS

Office (OOXML) / .XLSX

84.3 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: 1052a744e5016616dae680adc6f7c8d3 SHA-1: 532125fa8ca69cbdc36da1b41aad2e53c87b3775 SHA-256: d9fe9c268dabc421ee0cd7eb120d655552b34c05e482f213c19d76628eb37337
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file identified as containing Excel 4.0 macros. These macros are known to be used for malicious purposes, such as executing arbitrary commands or downloading further payloads. The extracted script content is heavily obfuscated and truncated, preventing a detailed analysis of its specific actions or the reconstruction of any URLs or commands. Therefore, the exact attack pattern and IOCs cannot be definitively determined.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
b720c3e58d718d87b0447b2b13ef32e1c3f4766609358494dda48055385586df
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 285255 bytes