Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 085b615773730535…

MALICIOUS

Office (OLE)

93.0 KB Created: 2010-07-08 03:44:22 Authoring application: Microsoft Excel First seen: 2015-02-05
MD5: 6dd6fbf153017422eb2093cecf3eb118 SHA-1: 9a3d3f6574d196a479a91fa171f34338df56dd81 SHA-256: 085b615773730535d7cccd4c31491c303a7b35e63b4ef06d8e67b0bf1f5a1ad2
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel file containing legacy Excel 4.0 macro (XLM) code, identified by the 'OLE_XLS_FORMULA_MACRO_VIRUS' heuristic. The macro code explicitly mentions infecting other workbooks and includes markers associated with the 'Poppy' Excel macro virus. The presence of this code suggests an attempt to spread and potentially download further malicious content.

Heuristics 2

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/ In document text (OLE body)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In document text (OLE body)
    • http://purl.org/dc/elements/1.1/In document text (OLE body)
    • http://ns.adobe.com/xap/1.0/mm/In document text (OLE body)
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In document text (OLE body)
    • http://ns.adobe.com/tiff/1.0/In document text (OLE body)
    • http://ns.adobe.com/exif/1.0/In document text (OLE body)
    • http://ns.adobe.com/photoshop/1.0/In document text (OLE body)
    • http://www.iec.chIn document text (OLE body)