Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 f9f2bbed4de79feb…

MALICIOUS

Office (OOXML)

82.8 KB Authoring application: Microsoft Excel 14.0300 First seen: 2021-04-01
MD5: c6b12cf2e12c54100737dba2b4d255ef SHA-1: b22db08a3b5a89362fe8173d3e875a097471c346 SHA-256: f9f2bbed4de79febceab8d23ae7e03a5520d6fe4df29d23ae663e799748dcda1
60 Risk Score

Heuristics 1

  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.