Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 137d616d30f5ab8c…

MALICIOUS

Office (OLE)

103.5 KB Authoring application: Microsoft Excel First seen: 2012-06-14
MD5: 06b0a04339be3320ed61cc1e25018ec6 SHA-1: 962d4d5b05f2609ae3cf661717c77f14df78ec62 SHA-256: 137d616d30f5ab8c87baa3a01a9830d39883cfd0806afb18a1f8e62b5fbf3aa9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is identified as a malicious Excel 5 macro-virus, specifically the Laroux family, by multiple heuristics. The presence of macro markers like 'auto_open' and 'OnSheetActivate' strongly indicates the execution of embedded Visual Basic for Applications (VBA) code. This code is likely responsible for downloading and executing a secondary payload, consistent with the 'Legacy.Trojan.Agent-487' detection.

Heuristics 2

  • ClamAV: Legacy.Trojan.Agent-487 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-487
  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.