Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 468a3f081700d8a0…

MALICIOUS

Office (OLE) / .XLS

540.5 KB Created: 1999-12-20 03:10:36 Authoring application: Microsoft Excel
MD5: 0791573c03784e7c39d06ffa22971b0d SHA-1: 8222daaf92a07422486c8c70c682e54b45ed955f SHA-256: 468a3f081700d8a00125efd9d2d520521bb2f0721d12d82c94b13417c6a5fff2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as a legacy Excel formula macro virus. While the document body contains technical terms related to soil mechanics, the critical heuristic firing strongly suggests the presence of malicious macro code. The specific markers found point to older, known macro viruses.

Heuristics 1

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.