Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 178505954b8d0e5d…

MALICIOUS

Office (OLE)

36.5 KB Created: 2020-11-25 10:43:23 Authoring application: Microsoft Excel
MD5: 0d6c2ffd29639c8fc1784615e302d75d SHA-1: 896733707843539e70207e4a57f56cd8a85fbaac SHA-256: 178505954b8d0e5d1f48f3c0e4ee73dd6ec596ad32f8a5a34ba633087d662b09
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The file is an Excel 4.0 macro sheet containing an Auto_Open function, which is a critical indicator of malicious intent. This function is designed to execute arbitrary code upon opening the workbook, commonly used to download and execute further malware. The presence of dangerous formula APIs like RUN further supports this conclusion.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
1bea3682567355a521155ac930f8915492f4205cf47cf7008645151d75ff4ec0
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6652 bytes