Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 3e9a5320b9d24f1a…

MALICIOUS

Office (OLE) / .XLS

387.5 KB Created: 2002-10-24 17:02:22 Authoring application: Microsoft Excel
MD5: 4f5bc7e16a35a8897c955109376c5c16 SHA-1: 4fa16f1ccd53ecd652c15da0fdce6a330b930b49 SHA-256: 3e9a5320b9d24f1accf5254b5f27fc7340308a56006fed220fccf87db7ffa75e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.005 Visual Basic

The file is an Excel spreadsheet containing a Workbook_Open VBA macro, a common technique for initial execution. The macro is designed to run automatically when the workbook is opened, indicating a likely attempt to deliver a secondary payload. The document body content appears to be financial transaction data, possibly used as a lure.

Heuristics 2

  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
592270ff08187ea6f61b1f76e3bfa9f2e9a7327bb4b92af596e98c48199a1e93
vba-macro oletools.olevba.extract_macros (decoded VBA source) 10196 bytes