Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e852bff96cb4f89f…

MALICIOUS

Office (OOXML) / .XLSX

371.5 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: 77ed2e723a9b226fdc1be0f39481672f SHA-1: a0cdaa49fd109092d0b7d7ade18b58b372db79e3 SHA-256: e852bff96cb4f89fdeadc87957142a07193e9e965019ebc5ace0190e5e6b91ed
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing Excel 4.0 macros. These macros are known to be used for malicious purposes, such as executing arbitrary commands or downloading additional payloads. No specific IOCs were extracted, and the macro content was truncated, limiting further analysis.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
8ef9cb6533eaff3acdbf7651ff1fa09521e2f3257fff30e5dfd665526a9ad355
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 613633 bytes