Barisada — Office (OLE) / .VLS malware analysis

Static analysis result for SHA-256 289736023e22fe1f…

MALICIOUS

Office (OLE) / .VLS

41.5 KB Created: 2003-07-18 13:24:35 Authoring application: Microsoft Excel
MD5: b02b146308572781c164c04d431ae9ce SHA-1: af1c93c74ac038afa1a6761f65d1e59fccf119f0 SHA-256: 289736023e22fe1fe71eebc46a50731e45b6002567e3bfaff73ec55e37dc8b46
180 Risk Score

Malware Insights

Barisada · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Xls.Trojan.Barisada-9. It contains VBA macros, specifically a Workbook_Open macro, which is a common technique for executing malicious code upon opening the document. The presence of VBA macros and the ClamAV detection strongly suggest a downloader or trojan functionality, likely related to the Barisada family. No specific URLs or further script details were extracted to detail the secondary payload.

Heuristics 4

  • ClamAV: Xls.Trojan.Barisada-9 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Trojan.Barisada-9
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
d2f6a5d0187efc3b37475a026dca91a7ce98493af9e732e8fd98579a94f6eb42
vba-macro oletools.olevba.extract_macros (decoded VBA source) 11362 bytes
Detection
ClamAV: Xls.Trojan.Barisada-2
Obfuscation or payload: unlikely