Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 1f28ed89a993d40f…

MALICIOUS

Office (OLE) / .XLS

690.0 KB Created: 2020-06-16 13:04:54 Authoring application: Microsoft Excel
MD5: b159f51c2a6e9d8b97a7d8dc29129175 SHA-1: f78cad0504982960fc91e1cb22731d3c6f681ad5 SHA-256: 1f28ed89a993d40f97a3e087f5fd73e6cb94358729e952cfbb69198121c25db9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1204.002 Malicious File

The presence of an OLE_XLM_AUTOOPEN heuristic indicates that Excel 4.0 macros are present and configured to run automatically. The OLE_XLM_DANGEROUS_FN heuristic specifically flags the use of dangerous functions like RUN, suggesting the macro is designed to execute arbitrary code. The embedded URLs, while currently classified as benign, are often used as initial staging points or for downloading further malicious content. The macro's intent is likely to download and execute a second-stage payload.

Heuristics 3

  • XLM Auto_Open with dangerous formula APIs high OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
b419e4bb09f68fd291436e425f94347e28b3817b2caf850f935d2b58edafdcaa
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 156293 bytes