Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 442b7623606e4ac0…

MALICIOUS

Office (OLE) / .XLS

201.5 KB Created: 1996-12-17 01:32:42 Authoring application: Microsoft Excel
MD5: d932dd816f001b61832fba69741ef5bc SHA-1: 494e69d6b82564cd4d072ae0a80370b4c8466781 SHA-256: 442b7623606e4ac0408b36a4160da89d95caf25acb22db566f4613d58e0f2ad8
200 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1105 Ingress Tool Transfer

The presence of an embedded SWF file within an OLE document, coupled with heuristic firings for VirtualAlloc, LoadLibrary, and GetProcAddress, strongly indicates the document is a loader for malicious code. The embedded SWF is likely responsible for downloading and executing a second-stage payload from one of the extracted URLs. The large slack space in the OLE structure is also a common characteristic of malicious documents designed to hide their true payload.

Heuristics 6

  • Embedded Adobe Flash (SWF) in OLE document critical OFFICE_EMBEDDED_SWF
    Document contains an embedded Adobe Flash (SWF) object. Vulnerabilities such as CVE-2018-4878 and CVE-2018-15982 involved Flash objects embedded in Office files. Adobe Flash has been end-of-life since December 2020.
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 206,336 bytes but its declared streams total only 24,565 bytes — 181,771 bytes (88%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Reference to VirtualAlloc API medium SC_STR_VIRTUALALLOC
    Reference to VirtualAlloc API
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.cyberglass.co.uk
    • http://www.hubeiquan.com/happy/heart.htm