Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 30b599f8110f4a5c…

MALICIOUS

Office (OLE) / .XLS

67.5 KB Created: 2015-06-05 18:19:34 Authoring application: Microsoft Excel First seen: 2022-05-23
MD5: 3264e16e2d21836e4087e76d0943b8b4 SHA-1: 525547db03f6c255882476ac9b16c305731b4ad1 SHA-256: 30b599f8110f4a5c63bd656e7fe30a405de553e221c48932aa9eaef5625c3b77
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Service Execution: Visual Basic T1204.002 Malicious Link/Object: Malicious File

The critical OLE_XLM_DANGEROUS_FN heuristic indicates the presence of dangerous Excel 4.0 macro functions, specifically the RUN function. The DOC BODY section reveals concatenated strings that reconstruct to multiple URLs, suggesting the macro's intent is to download and execute a second-stage payload. The Auto_Open entry further confirms the automatic execution of this malicious macro upon opening the document.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
67f6b164c4d6ea1ea8efe2ccdff056dde7fd1072da2bb20afe3b275864086c71
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 7678 bytes