Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 06492f0610cc247a…

MALICIOUS

Office (OLE) / .XLS

331.0 KB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel
MD5: d3e0d7c73eef049d88a71cb85c0b51ed SHA-1: 4a64186ef6177a0c7d8e6acf4b2fe73096ece4c9 SHA-256: 06492f0610cc247a17a5bddd73b4ecda4012f990b786041f1067fd7b8e22db4b
242 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The file contains Excel 4.0 macros with an Auto_Open entry, which is a critical finding indicating automatic execution upon opening. The macros utilize dangerous functions like RUN and CALL, and specifically reference ShellExecute, suggesting the execution of external code. The embedded URLs, such as https://bgms.co.in/ds/261120.gif, are likely used to download and execute a secondary payload. The macro logic attempts to construct a CALL to a function with arguments that include reconstructed strings like 'UR' and 'n', indicating a complex execution flow designed to evade detection.

Heuristics 6

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • ClamAV: Doc.Downloader.Docusign0521-9864805-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Docusign0521-9864805-0
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://bgms.co.in/ds/261120.gif
    • https://bgms.co.in/ds/261120.gif�

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
e213645668ce9f5d68f4226afb5b9b5e6c2ad49807658d9b833212b471c7c00d
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6675 bytes