Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 fcd0abafdfecfaae…

MALICIOUS

Office (OOXML) / .XLSX

294.4 KB Created: 2021-09-13 09:41:09 UTC Authoring application: Microsoft Excel 12.0000
MD5: 5acccbb96da51c569a79b646ff1ae8c9 SHA-1: 5adea3566d0d38d345a2a3512e6654f386efce39 SHA-256: fcd0abafdfecfaaed8d21ea0e8724600d0d76296bc2b31933cfc60041d710baf
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel 4.0 macro sheet, indicated by the OOXML_XLM_MACROSHEET heuristic. Excel 4.0 macros are capable of executing arbitrary commands, which is a common technique for initial access or downloading further malicious payloads. No specific family could be identified, and no IOCs were directly extractable from the macro content.

Heuristics 1

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
f3e84869881628809b863544264919d9481bf37ec84b200f7bdb452c05c73624
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 912 bytes