Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 52bffd82e35380de…

MALICIOUS

Office (OLE) / .XLS

36.5 KB Created: 2010-02-23 03:43:42 Authoring application: Microsoft Excel
MD5: e60f3c1c177b571a468840085e53838f SHA-1: 6eda6ad0325733b943b44963928a55447d8024c6 SHA-256: 52bffd82e35380defb17790b984cdeb46e39f429c74b8db3ab4bae42ec9587f4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1566.002 Spearphishing Attachment

The file is an Excel spreadsheet containing VBA macros, specifically an Auto_Open macro, which is a common technique for executing malicious code upon opening the document. The document body contains a mix of Hindi and English text that appears to be a lure, possibly related to payment or company information, encouraging the user to enable macros. No specific IOCs like URLs or hashes were extracted, but the presence of the Auto_Open macro strongly suggests an attempt to download and execute a secondary payload.

Heuristics 2

  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
8f90a26191379ac9feb61d3e2ceb48cb18f5fc6aee0fbbfe490c0970803c7c67
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1882 bytes