Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 13187493825a4f2d…

MALICIOUS

Office (OLE) / .EXE

48.5 KB Created: 1980-01-05 18:36:54 Authoring application: Microsoft Excel
MD5: d40b1cac6d7436a6927d8ae61ab9123c SHA-1: f8e9acebebb458e45ac887676fc2b0290dab3edf SHA-256: 13187493825a4f2da96e9c60e9063d8314520319cfbe6d4a34996aca07d93945
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for OLE_XLS5_LAROUX_MACRO_VIRUS indicates the presence of a malicious macro within an Excel 5 file. The presence of markers like 'auto_open' and 'OnSheetActivate' suggests the macro is designed to execute automatically. The document body content is minimal and does not provide further context on the specific payload.

Heuristics 1

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.