Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 4f372e105540e11f…

MALICIOUS

Office (OLE) / .XLS

509.5 KB Created: 1998-05-19 06:50:27 Authoring application: Microsoft Excel
MD5: cf21f245baccf621d60a6b2dbb34248f SHA-1: 0a33198254dc1f300e07c8d387aeaedbaa40e9b4 SHA-256: 4f372e105540e11fed199230b781270ecde6c478deef284dba0f8982a81094e0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is an older Excel XLS format and triggered a critical heuristic indicating it is a legacy Excel formula macro virus. The document body contains what appears to be an educational report template, likely intended to trick users into opening and enabling macros. No scripts were extracted, and no URLs were found, limiting further analysis of the payload.

Heuristics 1

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.