Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e6b94b21bcf4b6e1…

MALICIOUS

Office (OOXML) / .XLSX

348.7 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: ca5864075a59e0e794cf06b158fe3076 SHA-1: 65e0e5897c5b6be2569da7ace19af0c8c65d0894 SHA-256: e6b94b21bcf4b6e11369abd719f9197f69fc47b023ddf09ca6d0b572264877d7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing indicates the presence of an Excel 4.0 macro sheet. While the macro content is truncated, the presence of such macros is often used to download and execute additional malicious content. The specific actions of the macro could not be fully determined due to truncation.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
aefd34a7616ae64156e348457751457410a37836453da7100104b72b8090ec21
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 260677 bytes