Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 4e9244b5b2e9c389…

MALICIOUS

Office (OLE) / .DOC

214.0 KB Created: 2020-04-07 08:55:27 Authoring application: Microsoft Excel
MD5: a2f3c621988fd47dbd1e8ace97424c04 SHA-1: f39a7383e08663d866b0e42a5983c43431dcc553 SHA-256: 4e9244b5b2e9c3891b52564f7de40a073020e1c6e4b7e026d2f3cb7ffead57cc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel 4.0 macro-enabled document. Heuristics indicate the presence of an Auto_Open macro that uses dangerous functions, specifically the RUN function, to execute arbitrary code. The document body does not provide further context on the intended lure. No external URLs or scripts were extracted for further analysis.

Heuristics 3

  • XLM Auto_Open with dangerous formula APIs high OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.microsoft.com/photo/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
301c5fcdc8e98461b69c1412a0c726c9f8e374a14d4fc4fd15fc204706cfc30e
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 55235 bytes