Xls.Trojan.Laroux-28 — Office (OLE) / .EXE malware analysis

Static analysis result for SHA-256 1229fa2a2a38e118…

MALICIOUS

Office (OLE) / .EXE

69.0 KB Created: 1998-08-24 23:10:00 Authoring application: Microsoft Excel
MD5: 6fd0503aa7abf1e78b9bf495ef40c3f8 SHA-1: a83c171f6948a3a184967500bef985a948f78f92 SHA-256: 1229fa2a2a38e11817fd1978a56cfbba0432e3c3b53fb6a13db0427266ec569c
240 Risk Score

Malware Insights

Xls.Trojan.Laroux-28 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1547.001 Registry Run Keys / Startup Folder

The file is identified as a malicious Excel 5 macro-virus, specifically Xls.Trojan.Laroux-28. The VBA script contains an Auto_Open macro that sets up an event handler for sheet activation to execute the 'check_files' subroutine. This subroutine appears to be designed to save a file named 'PLDT.XLS' in the startup path, likely to establish persistence or facilitate further execution.

Heuristics 5

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.
  • ClamAV: Xls.Trojan.Laroux-28 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Trojan.Laroux-28
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
a5850330c65d4e31d8877e97d10657fea575d501c96cca7b0f2b7f3bb8b08c49
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2025 bytes
Detection
ClamAV: Xls.Trojan.Laroux-28
Obfuscation or payload: unlikely