Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 05bbaebeaecfb2c6…

MALICIOUS

Office (OLE) / .XLS

1.14 MB Created: 2007-06-12 16:12:52 Authoring application: Microsoft Excel
MD5: c8d8de6b8116e02e5fefb9f3c2c924db SHA-1: 21b74e8cd70954cb7d7b695cac831a022a015cc6 SHA-256: 05bbaebeaecfb2c6ecd3f53c596a40402b380d93d40140b1b7d35ac9ac50b6f3
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1547.001 Registry Run Keys / Startup Folder

The critical ClamAV detection and high-severity heuristic for an Auto_Open macro indicate malicious intent. The VBA script within the sample attempts to achieve persistence by saving a copy of itself as 'mypersonnel1.xls' into the Excel startup path, which is a common technique for malware to ensure it runs automatically. The script also manipulates application settings to hide its actions.

Heuristics 3

  • ClamAV: Xls.Virus.Valyria-10004391-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Virus.Valyria-10004391-0
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
e538b19efeea4079cccb552f0d271cfd06e53dea0bbce6b4139c83fed4041abb
vba-macro oletools.olevba.extract_macros (decoded VBA source) 183634 bytes