Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 dbb9b1dff45c1101…

MALICIOUS

Office (OOXML) / .XLSX

68.6 KB Created: 2021-03-14 21:03:54 UTC Authoring application: Microsoft Excel 16.0300
MD5: 58e423c70460ff2e8d8b1ffe2b16400f SHA-1: c48df391a979e4db06d05f70962ef828beb51dd0 SHA-256: dbb9b1dff45c110189b9a553a73457e2143173cfa0ae82ffa176d490b2c33212
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing a macro sheet, identified by the OOXML_XLM_MACROSHEET heuristic. The macro sheet appears to be truncated, but the presence of Excel 4.0 macros indicates an intent to execute commands. Without further deobfuscation or content, the specific payload and delivery mechanism remain unclear, leading to an unknown family classification.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
dfd4bd296920dc9f739306eee5c514d939078c8a6d35a3e7bf5c344468cf9aef
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 92099 bytes