Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 daeb973d54237b01…

MALICIOUS

Office (OOXML) / .XLSX

129.8 KB Created: 2015-06-05 18:19:34 UTC Authoring application: Microsoft Excel 16.0300
MD5: a498dbec2608c9ea9a6a699c7419aaf0 SHA-1: 9aa5f7faeff21ee988c06f7b267e15c21b083bc5 SHA-256: daeb973d54237b01e89ee0ed02eb75a6c4965e445e796e67c377c2a76bd5d4d8
180 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1105 Ingress Tool Transfer

The file is an Excel document containing multiple Excel 4.0 macro sheets, identified by the OOXML_XLM_MACROSHEET and OOXML_XLSB_INTL_MACROSHEET_IN_XLSX heuristics. The extracted macro content, though partially truncated, contains strings like 'URLDownloadToFileTo' which strongly suggests the intent to download a second-stage payload from a remote source. The ClamAV detection further confirms its malicious nature as a downloader.

Heuristics 3

  • Excel 4.0 macro sheet (13 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.
  • XLSB international XLM macro sheet hidden in .xlsx critical OOXML_XLSB_INTL_MACROSHEET_IN_XLSX
    OOXML package is named .xlsx but contains XLSB workbook parts and an international Excel 4.0 macro sheet. This hides XLM macro execution from scanners that trust the extension or only inspect XML worksheet parts. The technique is macro execution, not a document-parser CVE.
  • ClamAV: Xls.Downloader.GreenOffice01220-9937699-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.GreenOffice01220-9937699-0

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
1686ce2c491a649c345a9500895dd65862f39771e436e7cb20d9e03e00be19fd
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet1.bin 363 bytes
xlm_sheet_01.bin
a529dae7d8bdfed5805bdcf1fc60f52b2d3375146b8fb813abcc455feade132b
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet2.bin 632 bytes
xlm_sheet_02.bin
5dcbd7dc9e28eff6ca1489493649e07dcf47b5ec1076570d73081f691977fbc3
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 2762 bytes
xlm_sheet_03.bin
3322e059eba46e942fe7c99ae5febfeeb58d1e7067185a4fa590c0379d72ff10
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet3.bin 1701 bytes
xlm_sheet_04.bin
138dfffc4dc4262a3f197627d3027e6ba195a73cad3290df46727b676fe2283c
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet4.bin 675 bytes
xlm_sheet_05.bin
2e300f6e7ac4d1d915d7b3601a17a26d203f390a17150e1c07e894392ea98a10
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet5.bin 720 bytes
xlm_sheet_06.bin
cfbad5d0aafd4fefa3942c1874dc9e6267e8c195c45232bd3d9fadce9693089d
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet6.bin 826 bytes
xlm_sheet_07.bin
7da484251d8ff7a8859876e2465fea33f9a698b8d66355e82a953026c27401ef
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet7.bin 552 bytes
xlm_sheet_08.bin
b50a4c21bf7e3c1c167e9126c04f574ffee76408017d18e2651b1f275f4e4015
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet8.bin 483 bytes
xlm_sheet_09.bin
e8dde2fe7299fe5c29f354689bbc2e0de8d59e920351db2c3c3e5572ed8a1618
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet2.bin 856 bytes
xlm_sheet_10.bin
d4c560579f32f1046c57818eed9c1c3451a96b91d798e1b2a8d256a98c394728
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet3.bin 810 bytes
xlm_sheet_11.bin
8be06878766f561b6355428b8ab25e3928e646756c3c1bf8d87ed41cac091d5b
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet4.bin 821 bytes
xlm_sheet_12.bin
d626e9b87216fc097abb2cbaec60ac53c6366a9f2a130d478e077a019d52c6b0
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/intlsheet9.bin 679 bytes