Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e7ffee57698aeb8f…

MALICIOUS

Office (OOXML) / .XLSX

64.1 KB Created: 2021-03-14 21:05:29 UTC Authoring application: Microsoft Excel 16.0300
MD5: 307bb8ba033af4ecc5627763607084e6 SHA-1: b3b0124507b1fb28f03d9949c75b1fe65e1fc07a SHA-256: e7ffee57698aeb8ff7211cbe321e3e5b17c20bc6549916ce651015c2bf6816c3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing Excel 4.0 macros. The heuristic firing indicates the presence of these macros, which are often used to download and execute malicious payloads. The script content is heavily obfuscated and truncated, preventing a detailed analysis of its specific actions or the reconstruction of any URLs or commands. Therefore, the exact attack pattern and family remain uncertain.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
7f0ba06904c224fe0a4e7d13ff8436444b1167f592db8b42038afc21e58f04f1
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 88880 bytes