Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e9210de0b730ef35…

MALICIOUS

Office (OOXML) / .XLSX

69.3 KB Created: 2021-03-14 21:05:29 UTC Authoring application: Microsoft Excel 16.0300
MD5: b47e26e5346c0f9adb6ce6de7211a86b SHA-1: 521045d971726a40e237c313d2d916a6312ba759 SHA-256: e9210de0b730ef35355f341c3cd2fa4686f3a36668fa14cde20d0c65f643865f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications

The sample is an XLSX file identified as containing Excel 4.0 macros. While the macro content is heavily obfuscated and truncated, the presence of these macros strongly suggests an intent to execute arbitrary code. The primary heuristic firing confirms the presence of these macros, indicating a likely download and execution attack pattern. Without further deobfuscation or network indicators, the specific family and payload remain unknown.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
5d37c6b3a87f9afe7565728bed44ec6f54724bbd67380b37771d6ac40c824512
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 88880 bytes