Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 fbff49100ec05232…

MALICIOUS

Office (OOXML) / .XLSX

20.0 KB Created: 2021-08-10 06:23:53 UTC Authoring application: Microsoft Excel 15.0300
MD5: 98c1aa48f8b9ba8eacfeeef180ad7ba1 SHA-1: bc0f6809993f02457a873a6306caded55382745c SHA-256: fbff49100ec0523290c80ae279c0202540c1f5e939e39c571cfc09e46bc012b0
260 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.003 Windows Command Shell T1204.002 Malicious File

The file is an Office document containing VBA macros, specifically a Workbook_Open macro that triggers obfuscated VBA code. Critical heuristics indicate the use of Shell() and WScript.Shell, suggesting the macro attempts to execute external commands or download and run additional malware. The VBA code is truncated, but the presence of these indicators strongly points to a downloader or initial execution stage.

Heuristics 6

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
20dca33689867fb61e2caa30440632cff7741e5e8ccd4f0b168e59812e22a6a2
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 8090 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 6 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.
vbaProject_00.bin
c33caa28d102a71888dd03ab8efc724db2db23c78909a5e9a55c616a353f5b10
vba-project OOXML VBA project: xl/vbaProject.bin 28160 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s). Carved artifact contains 6 long base64-like blob(s). Carved macro source contains an auto-exec entry point and execution/download terms.