Malicious Office (OLE) / .LAR — malware analysis report

Static analysis result for SHA-256 4edc6ebc45dd399d…

MALICIOUS

Office (OLE) / .LAR

20.0 KB Created: 2001-10-14 19:57:46 Authoring application: Microsoft Excel
MD5: 2964db460124fd2775ff865e9450334e SHA-1: e757ea83024554ccfee711a932ccfbd442c321e1 SHA-256: 4edc6ebc45dd399d5d6adcd89aea5e995bed37f9baf101f29470f4f967b6c460
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.005 Visual Basic

The file is an Excel spreadsheet containing a VBA macro. The 'Auto_Open' heuristic indicates that this macro is designed to execute automatically when the document is opened. No specific IOCs were extracted, but the presence of an auto-executing macro strongly suggests a malicious intent, likely for initial execution of further stages.

Heuristics 2

  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
28c6fd76bdd5a67a6f64b05b87032fee7949f8c4748c4c1ab7100fdc80ff2f35
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1593 bytes