Malware Insights
The file is an XLSM document containing Excel 4.0 macros, as indicated by multiple critical heuristic firings including OOXML_XLM_MACROSHEET and OOXML_XLM_DANGEROUS_FN. The macros utilize the FORMULA API to construct URLs and download a file named 'bestb.ocx' to the system. The reconstructed URLs are http://maedavenport.com/wp-content/Tu2oM6gLSXmVtJs9oFzXd/, http://gulfstreamchem.com/wp-content/7R2YvoMN/, and http://boardingschoolsoftware.com/Vineet_Backup/fhYT87P/. The macros then attempt to execute the downloaded file using rundll32.exe. This behavior is consistent with the Emotet malware family, which often uses macro-enabled documents to download and execute further stages.
Heuristics 6
-
Excel 4.0 macro sheet (7 sheet(s)) critical OOXML_XLM_MACROSHEETSpreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks.
-
Excel 4.0 Auto_Open defined name critical OOXML_XLM_AUTOOPEN_DEFINEDNAMEWorkbook defines _xlnm.Auto_Open or _xlnm.Auto_Close while containing an XLM macro sheet. This is the OOXML/XLSB auto-execution shape for Excel 4.0 macros.
-
Dangerous XLM formula APIs: FORMULA critical OOXML_XLM_DANGEROUS_FNExcel 4.0 macro sheet uses formula APIs that call directly into Win32 (=CALL/=EXEC/=REGISTER/=FORMULA). These are the primitives used to download payloads, write files, and start processes from an XLM macro without invoking VBA.
-
ClamAV: Xls.Downloader.EmotetExcel122100-9913103-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Xls.Downloader.EmotetExcel122100-9913103-0
-
Hidden worksheet (hidden) low OOXML_HIDDEN_SHEETExcel workbook contains 11 hidden sheet(s) — hidden sheets are commonly used to conceal macro code, staging data, or intermediate payload construction
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/spreadsheetml/2006/main
- http://schemas.microsoft.com/office/excel/2006/main
- http://schemas.openxmlformats.org/officeDocument/2006/relationships
- http://schemas.openxmlformats.org/markup-compatibility/2006
- http://schemas.microsoft.com/office/spreadsheetml/2009/9/ac
- http://schemas.microsoft.com/office/spreadsheetml/2014/revision
- http://schemas.microsoft.com/office/spreadsheetml/2015/revision2
- http://schemas.microsoft.com/office/spreadsheetml/2016/revision3
- http://schemas.microsoft.com/office/spreadsheetml/2016/revision6
Extracted artifacts 7
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
xlm_sheet_00.xml539c2f7c8916fb96a053023d48fc5fd54085de1e0dda4336a9d7bfab3a7e3203 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/intlsheet1.xml | 3139 bytes |
xlm_sheet_01.xml1d840e58b613d5aaf0c1584ddad983c459013d0020172bf8c42753a3ca5c10ce |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet1.xml | 1367 bytes |
xlm_sheet_02.xml9530473eeb7ce4531ba6f2fb74f3f8b15d5970a3f986b2de8204ee4e69d17bcb |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet2.xml | 1367 bytes |
xlm_sheet_03.xml5298b05c0f3d1a953d0ede7427cc089251a7652227e518fae265a133c04b11f5 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet3.xml | 1364 bytes |
xlm_sheet_04.xml5f53215a8438bb7fe5a809106144bae36a7af9a316481ee676680c60ac4893c6 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet4.xml | 1364 bytes |
xlm_sheet_05.xml466ccb4b7c309940a771659ee00d4db755bdde38abf836c5ee99a946f296d356 |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet5.xml | 1367 bytes |
xlm_sheet_06.xml85d88333fb0430df1cb4b286e0f1d952b0e36ae77f3e113b23aadd6e029134fc |
xlm-macrosheet | OOXML XLM macro sheet: xl/macrosheets/sheet6.xml | 1366 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.