.. /.Xlsb

Phishing
Double Click
External
Exploit

Author:

mr.d0x

Description:

XLSB or Excel Binary Spreadsheet is an uncompressed binary Excel file. Similarly to XLS files, it can contain malicious macros.

OS:

Windows
Mac

Recommendation:

Disable macros via GPO and whitelist the users that are permitted to run macros. For end users, turn off macros from Excel's settings.

Resources:

https://malware.news/t/xlsb-analyzing-a-microsoft-excel-binary-spreadsheet/46442
https://www.hornetsecurity.com/en/threat-research/qakbot-distributed-by-xlsb-files/

File Samples:

https://www.joesandbox.com/analysis/445525/0/html

Contributions: