Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 f55ad933ae92867b…

MALICIOUS

Office (OOXML) / .XLSX

349.5 KB Created: 2021-08-16 09:36:27 UTC Authoring application: Microsoft Excel 12.0000
MD5: db19b58388e9c977326d7ace50b667dd SHA-1: ae9ab714c107561a1f6fd70e04b505af8753aae1 SHA-256: f55ad933ae92867b23e21b49ff6a02b97213c748b400458d3b995a82ccb39810
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications

The sample is an Excel file containing Excel 4.0 macros. The heuristics indicate the presence of macro sheets, which are often used to execute arbitrary commands. No specific URLs or further script details were extracted due to truncation, limiting the ability to determine the exact payload or delivery mechanism.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
de9f626d8a268c829fd0a110ab8fe597376160bb3fad39d294110bf0492a61e2
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 231807 bytes