Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 2b57b2c6b75db329…

MALICIOUS

Office (OLE) / .XLS

461.5 KB Created: 2000-05-26 16:45:09 Authoring application: Microsoft Excel
MD5: cec821fbdfaffc76a6dd42ab8b303a0a SHA-1: 99c2d234af2970472b1acc67f804ae521ff301cd SHA-256: 2b57b2c6b75db329e274dc788498e4ca1b54c992232055ef2a53cae240cb6883
80 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is an Excel spreadsheet containing VBA macros, as indicated by the OLE_VBA_MACROS heuristic. The ClamAV detection further confirms its malicious nature. The document body contains financial and construction-related terminology, suggesting a lure to entice users to open and interact with the spreadsheet. The VBA macros are the primary mechanism for the attack, likely downloading and executing a secondary payload.

Heuristics 2

  • ClamAV: Xls.Malware.Generic-6680536-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Generic-6680536-0
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
39cc95f47975db063e6ff081aa9c01a4f46cfcb0ddfedc38d680e375cf95b6ee
vba-macro oletools.olevba.extract_macros (decoded VBA source) 10237 bytes