Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 df9867b55f1e56af…

MALICIOUS

Office (OOXML) / .XLSX

112.8 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: b6378db23ca125de2566b7e7d06f0eee SHA-1: 81d279e1c574d8f1ad15d5ba5a78c3f0c8117366 SHA-256: df9867b55f1e56af65458aead4ed15464608cd5c11dede7e15a3d0e9d8fdab95
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of Excel 4.0 macros within the XLSX file. While the macro content is truncated and obfuscated, this technique is commonly used to download and execute further stages of malware. The absence of specific IOCs or clear script functionality limits further analysis.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
44986e92162aa0d4c07d03cebf85b8d6ae18344c65d5f7aaa8f8f95c6a561226
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 325765 bytes