Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 03c7e8f8c0fb14de…

MALICIOUS

Office (OLE)

36.0 KB Created: 2020-11-27 11:47:03 Authoring application: Microsoft Excel
MD5: e002db7782467d0b8683c12c44670076 SHA-1: 6fc7115644a6439350f5fa1488f70d2b22b468ef SHA-256: 03c7e8f8c0fb14dee2b7f66aeb57192e50a26c6fff70c4dc160fb63c04f76e57
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristics indicate the presence of Excel 4.0 macros with an Auto_Open entry, which is a common method for executing malicious code within older Excel versions. The macro sheet contains a dangerous formula API, specifically identified as 'RUN', suggesting it is designed to execute arbitrary commands or payloads. The document body contains heavily obfuscated text, further indicating an attempt to hide malicious activity.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
daf736bfe64ddb5a71437b72a8d1c0ca6bc6e680e8159c4b90ae31cdcdf3a7c1
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6815 bytes