Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 38cb631b5cd3c4a3…

MALICIOUS

Office (OLE) / .XLS

163.0 KB Created: 2009-07-24 00:56:00 Authoring application: Microsoft Excel
MD5: 77ff63f71b3788da7ad9ef2f1910f8bd SHA-1: 24f13508f7d4a2bd674a093c6169b318ba8a1f71 SHA-256: 38cb631b5cd3c4a3ffbfb5b95b179d65e10ce241f26f69474b3223262dadc43b
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1059.001 PowerShell T1204.002 Malicious File

The critical heuristic OLE_XLM_DANGEROUS_FN indicates the presence of an Excel 4.0 Auto_Open macro that uses dangerous functions, specifically identified as 'RUN'. This suggests the macro is designed to execute arbitrary commands. The presence of an Auto_Open entry further confirms that this macro will execute automatically upon opening the workbook. The document body content is largely unreadable and does not provide further context on the specific lure.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
71eb283ea50be84a4e1ac4ff7f470304cb579c85f515d44210e4305c212c9f93
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 78120 bytes