Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 f5beeb404593b7d7…

MALICIOUS

Office (OOXML) / .XLSX

67.6 KB Created: 2021-10-27 10:31:49 UTC Authoring application: Microsoft Excel 12.0000
MD5: fe18dc6edf43ad57865b2661b539c280 SHA-1: e7978729137a9ab22870b32173753453c7a361e8 SHA-256: f5beeb404593b7d72f2ecabe258f2f9f1078d4205813c4bbf40e5b3d81f7f392
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel 4.0 macro sheet, indicated by the 'OOXML_XLM_MACROSHEET' heuristic. Excel 4.0 macros are capable of executing arbitrary commands, which is a common technique for downloading and executing further malicious payloads. No specific IOCs were extracted, and the macro content was heavily truncated, limiting the ability to determine the exact payload or family.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
93ce23876cb0c1be26b36dfa3583e9728f2c63f41e2b1c0c0989180994b32010
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 7119 bytes