Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 0e9cd108f2002ecc…

MALICIOUS

Office (OLE) / .XLS

458.0 KB Created: 2014-03-03 23:01:47 Authoring application: Microsoft Excel First seen: 2022-03-04
MD5: 87d2927417a842700153fc81973d306d SHA-1: 796eecfd07b4abec4d6b4386059e6713b24ad3fc SHA-256: 0e9cd108f2002eccf04e220694236b390d0cb19c496d90fbcae25d3850aa6866
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1140 Deobfuscate or Obfuscate Malicious Files or Information

The sample contains VBA macros and presents itself as a document related to user account management and firm details, including phone numbers for help desks. The VBA macros likely execute code to download and execute a second-stage payload, as indicated by the CreateObject heuristic and the presence of embedded URLs. The callback phishing lure heuristic further suggests a social engineering attempt to trick the user into interacting with malicious infrastructure.

Heuristics 4

  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=172099&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=172100&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=99746&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=135870&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=105672&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=135795&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=135856&&R=secure
    • https://www.mercergimd.com/secure/manager/PeopleDetails.asp?1=37279&&3=162784&&R=secure�
    • https://www.mercergimd.com/secure/product/InvestmentProductAbout.asp?1=
    • https://www.mercergimd.com/secure/product/ProcessStyle.asp?1=
    • https://www.mercergimd.com/secure/product/StrategyDetails.asp?1=�
    • https://www.mercergimd.com/secure/product/ProductAssets.asp?1=�
    • https://www.mercergimd.com/secure/product/Performance.asp?1=�
    • https://www.mercergimd.com/secure/product/Vehicles.asp?1=
    • https://www.mercergimd.com/secure/manager/About.asp?1=�
    • https://www.mercergimd.com/secure/asset/AssetsUnderManagement.asp?1=�
    • https://www.mercergimd.com/secure/manager/FirmHistory.asp?1=�
    • https://www.mercergimd.com/secure/manager/Owners.asp?1=
    • https://www.mercergimd.com/secure/manager/Litigation.asp?1=
    • https://www.mercergimd.com/secure/manager/EmpCompensation.asp?1=�
    • https://www.mercergimd.com/secure/manager/RiskMgmt.asp?1=
    • https://www.mercergimd.com/secure/manager/esg.asp?1=�
    • https://www.mercergimd.com/secure/product/vehicledetails.asp?1=
    • https://www.mercergimd.com/secure/product/vehiclefees.asp?1=�
    • https://www.mercergimd.com/secure/manager/About.asp?1=
    • https://www.mercergimd.com/secure/asset/AssetsUnderManagement.asp?1=
    • https://www.mercergimd.com/secure/manager/FirmHistory.asp?1=
    • https://www.mercergimd.com/secure/manager/EmpCompensation.asp?1=
    • https://www.mercergimd.com/secure/manager/esg.asp?1=
    • https://www.mercergimd.com/secure/product/StrategyDetails.asp?1=
    • https://www.mercergimd.com/secure/product/ProductAssets.asp?1=
    • https://www.mercergimd.com/secure/product/Performance.asp?1=
    • https://www.mercergimd.com/secure/product/vehiclefees.asp?1=

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
1a61d6249f91802b0043f4f464214bcd40485f2f69e8b1817ed2e168773dffba
vba-macro oletools.olevba.extract_macros (decoded VBA source) 8232 bytes