Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 3c04b4be919a1f17…

MALICIOUS

Office (OLE) / .XLS

433.0 KB Created: 2003-05-17 03:09:04 Authoring application: Microsoft Excel First seen: 2026-05-10
MD5: 5ad096d4cccb8de233b3a013e8e71217 SHA-1: 8f02bce5876202089cf49fac1091423450a91d4d SHA-256: 3c04b4be919a1f1729d1ac18990ecc2e4ed74bc088aacc05cf111d8cec8770ce
80 Risk Score

Heuristics 2

  • Legacy XLM macro-virus family marker critical OLE_XLM_LEGACY_MACRO_VIRUS
    Workbook contains an Excel 4.0 macro sheet and legacy macro-virus family or workbook-replication strings. This is a narrow indicator for infected XLM workbooks rather than ordinary formula use.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.