Xls.Trojan.Laroux-28 — Office (OLE) / .XLS malware analysis

Static analysis result for SHA-256 4a5e6e0f1114170b…

MALICIOUS

Office (OLE) / .XLS

35.5 KB Created: 2001-08-27 17:40:39 Authoring application: Microsoft Excel
MD5: bb2abb3c1c8d4508f37bee16dc30ac6e SHA-1: 969248ba89b62cdbc0efe8864a998e1fbba7463e SHA-256: 4a5e6e0f1114170bed6cc27f34c364a763cf819524a8eb173f9a80c837793f48
180 Risk Score

Malware Insights

Xls.Trojan.Laroux-28 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1566.002 Spearphishing Attachment

The file is identified as Xls.Trojan.Laroux-28 by ClamAV, indicating a known malicious Excel macro trojan. The presence of an Auto_Open macro strongly suggests that upon opening the spreadsheet, the user will be prompted to enable macros. If enabled, the macro is designed to execute malicious code, likely to download and execute a secondary payload from a remote source. The embedded URL, while confirmed benign, is often a component of the delivery mechanism for such threats.

Heuristics 5

  • ClamAV: Xls.Trojan.Laroux-28 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Trojan.Laroux-28
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.apple.com/DTDs/PropertyList-1.0.dtd

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
1ab6eecef12ad4852e62fbd2aaaacd824258ad494f2943ad3bc657703635aee5
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2028 bytes
Detection
ClamAV: Xls.Trojan.Laroux-28
Obfuscation or payload: unlikely