Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 1aa25d038b5184de…

MALICIOUS

Office (OLE) / .XLS

29.5 KB Created: 2010-06-08 02:57:03 Authoring application: Microsoft Excel
MD5: 8434f0ef14e1424e9a614b64a7657942 SHA-1: 2cf7b3c7130f2d16250878ba1b11f3e24cc89e87 SHA-256: 1aa25d038b5184de6e1a20b20152b97a96fec78385fed5ef3b97a24c3c39fdd2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as malicious by ClamAV with the Eicar-Test-Signature, a standard test for anti-malware engines. The document body contains a large list of names, which is likely a decoy or part of a social engineering lure. No scripts were extracted, and the primary indicator is the EICAR signature itself.

Heuristics 1

  • ClamAV: Eicar-Test-Signature critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Eicar-Test-Signature

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ole10native_00.bin
b86925338d9b02aa1aeea9606e1e8b874376cd64fb6fbfc669545ea69ed6b263
ole-package OLE Ole10Native stream: MBD0002A8BA/Ole10Native 512 bytes