Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 25609890daadae1c…

MALICIOUS

Office (OLE) / .XLS

111.1 KB Created: 1996-12-17 01:32:42 Authoring application: Microsoft Excel
MD5: 8bcb566ab6def67f13c65738417ce780 SHA-1: da4db9142a660a9cd65da3f5d6b2dba22707a826 SHA-256: 25609890daadae1ca19263738a34b5d1b2dba09d22fc83daa4434f7ed9f379a7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell

The sample is an XLS file with a large amount of slack space, indicating potential obfuscation or embedded content. A high-severity heuristic detected a suspicious invocation of cmd.exe with an execution flag, suggesting the execution of arbitrary commands. Additionally, PEB access was observed, which is often used by malware to evade detection. The embedded URLs, while some are benign, point to a domain that is unknown and potentially malicious, likely serving as a download source for a secondary payload.

Heuristics 4

  • PEB access via FS segment (x86) high SC_PEB_ACCESS
    PEB access via FS segment (x86)
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 113,726 bytes but its declared streams total only 24,565 bytes — 89,161 bytes (78%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.pdf-repair.com
    • http://www.pdf-repair.com)/Producer(Advanced
    • http://www.pdf-repair.com)/ModDate(D:20100406171120+08
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/