Xls.Trojan.PTH-2 — Office (OLE) / .XLSX malware analysis

Static analysis result for SHA-256 3e22454414d7a837…

MALICIOUS

Office (OLE) / .XLSX

61.0 KB Created: 1999-07-26 08:28:42 Authoring application: Microsoft Excel
MD5: 6c4d5d1e39269a6ca7f5b95d1771e770 SHA-1: 44915e2fef682ceefdb9fd901aaa004636554333 SHA-256: 3e22454414d7a83797cef6083f49474a9225a0ffd1cf19d8fe83a263e95717ac
240 Risk Score

Malware Insights

Xls.Trojan.PTH-2 · confidence 95%

MITRE ATT&CK
T1547.001 Registry Run Keys / Startup Folder T1059.005 Visual Basic

The file is identified as a malicious Excel macro-virus (Xls.Trojan.PTH-2) by ClamAV. The Auto_Open macro attempts to copy itself to the user's PERSONAL.XLS file, a common technique for establishing persistence. The script also manipulates Excel's event handling, specifically using OnSheetActivate and OnTime, to ensure its execution. The presence of 'laroux' markers further confirms its nature as a macro-based threat.

Heuristics 5

  • Excel 5 Laroux macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains the Laroux macro-virus marker cluster including the hidden laroux module, auto_open/check_files routines, and PERSONAL.XLS replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.
  • ClamAV: Xls.Trojan.PTH-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Trojan.PTH-2
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
ad14f4bc271411892dc248885c33e97cfdf7dbcddbbdee4b66ea73df5ac0a441
vba-macro oletools.olevba.extract_macros (decoded VBA source) 5396 bytes
Detection
ClamAV: Xls.Trojan.PTH-2
Obfuscation or payload: unlikely