Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 3334d60af4124f61…

MALICIOUS

Office (OLE)

123.0 KB Created: 2010-09-28 09:04:30 Authoring application: Microsoft Excel First seen: 2014-03-15
MD5: 8b2730bd35cf48ac246b3e918bffc542 SHA-1: 22b351d0e69bd82ffb58cb43c0eb49169a736f80 SHA-256: 3334d60af4124f612a21e4cee2324bcc84b2bfa1646d83cf063d48df536cf065
122 Risk Score

Heuristics 4

  • URL reconstructed from XLM cell array (1 URL) critical OLE_XLM_CELL_ARRAY_URL
    Excel 4.0 macro sheet stages its payload URL across the BIFF8 Shared String Table (one quoted-char SST entry concatenated with & at runtime), across individual numeric cells (one ASCII charcode per cell), or split across multi-char fragment cells a download formula concatenates by reference (=A1&A2&… / CONCATENATE(...)). The reconstructed URL is invisible to literal-bytes URL extraction because it is never contiguous in the workbook stream. URLs were recovered by walking the BIFF8 record stream and decoding SST entries, LABELSST/RK/NUMBER cells, and FORMULA cell-reference concatenation in token order.
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.hydrocost.org.cn/。 Referenced by macro