Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 344212406b66b6f8…

MALICIOUS

Office (OLE) / .EXE

25.0 KB
MD5: 1f5eb9e2ac8f91d0fdc4f0839b5eb06a SHA-1: 55def2f036a5e51509b5b698240f89f8e1c57053 SHA-256: 344212406b66b6f822fbaa2078f23af6c085b85204f48806bdb931b892e4269f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for OLE_XLS5_LAROUX_MACRO_VIRUS, along with the presence of 'laroux' in the document body, strongly suggests the presence of the Laroux macro virus. This type of malware typically automates malicious actions within Excel spreadsheets. No specific IOCs like URLs or hashes were extracted from this sample.

Heuristics 1

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.