Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 1910c39e0029b6aa…

MALICIOUS

Office (OLE) / .EXE

36.0 KB Created: 1999-02-08 09:24:15 Authoring application: Microsoft Excel
MD5: f386e3069c0428ec8b9fcac9d4aac5fe SHA-1: 13f6487ca0f3c4ab867e4e655db576378033d670 SHA-256: 1910c39e0029b6aa1198cdc39c4e27c317e3b4f418c875209a2c92adc4f80a4b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for OLE_XLS5_LAROUX_MACRO_VIRUS indicates the presence of the Laroux macro-virus, a known threat. The file is an Excel 5 OLE file, and the presence of macro-related markers strongly suggests malicious VBA code execution. No specific IOCs were extracted, but the nature of the threat is clear.

Heuristics 1

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.