Xls.Dropper.Agent-7084314-0 — Office (OLE) malware analysis

Static analysis result for SHA-256 56b50146fd6cca67…

MALICIOUS

Office (OLE)

834.1 KB Created: 2003-07-13 10:04:24 Authoring application: Microsoft Excel First seen: 2019-05-16
MD5: c556c137dc30ed12f2691f5a6b15d8ed SHA-1: 5f0743779cce5d90379b76b38b9c86f1fda31f2c SHA-256: 56b50146fd6cca6764bfed5144fc3e26d1e88099b349455e2d2cbcf919995848
582 Risk Score

Malware Insights

Xls.Dropper.Agent-7084314-0 · confidence 95%

MITRE ATT&CK
T1204.002 Malicious File T1105 Ingress Tool Transfer

This OLE document exhibits critical findings including an embedded PE executable and suspicious static triage signals, strongly suggesting it functions as a dropper. The presence of references to CreateProcess, ShellExecute, and URLDownloadToFile APIs indicates the file's intent to download and execute a secondary payload. ClamAV detections further corroborate its malicious nature as a dropper agent.

Heuristics 13

  • ClamAV: Xls.Dropper.Agent-7084314-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.Agent-7084314-0
  • Reference to URLDownloadToFile API critical SC_STR_URLDOWNLOAD
    Reference to URLDownloadToFile API
  • Embedded PE executable critical OLE_EMBEDDED_EXE
    MZ/PE header found inside document — possible embedded executable
  • Embedded Office document has suspicious static findings critical EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE
    A CFB/OLE Office document was found inside another file type and its carved contents matched Office exploit or payload heuristics. This catches wrapped exploit documents where the top-level file routes to a PE, archive, or generic scanner instead of Office.
  • Reference to CreateProcess API high SC_STR_CREATEPROCESS
    Reference to CreateProcess API
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 854,136 bytes but its declared streams total only 12,288 bytes — 841,848 bytes (99%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Reference to VirtualProtect API medium SC_STR_VIRTUALPROTECT
    Reference to VirtualProtect API
  • CFB header with no readable streams medium OLE_PARSE_EMPTY_STREAMS
    The file begins with a valid OLE2/CFB header but exposes no directory streams. A non-empty compound document with an unreadable directory is anomalous — it is seen with truncated/corrupt files and, more importantly, with content deliberately shifted off byte boundaries to defeat parsers while the host application still recovers the object.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0 In document text (OLE body)
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In document text (OLE body)
    • http://crl.verisign.com/tss-ca.crl0In document text (OLE body)
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OIn document text (OLE body)
    • http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0In document text (OLE body)
    • http://office.microsoft.comIn document text (OLE body)
    • https://www.verisign.com/rpaIn document text (OLE body)
    • https://www.verisign.com/rpa01In document text (OLE body)
    • http://crl.verisign.com/pca3.crl0In document text (OLE body)
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DIn document text (OLE body)
    • https://www.verisign.com/rpa0In document text (OLE body)
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0In document text (OLE body)
    • http://windowsmedia.com/redir/xpsample.aspIn document text (OLE body)

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_0000660a.exe embedded-pe Office MZ+PE at offset 0x660A 828014 bytes
SHA-256: f767593ef497605457216382fb405f603c81d5c525df838e9bdee8eacda83a04
Detection
ClamAV: Win.Trojan.Agent-6943819-1
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): cmdln
embedded_office_off00003605.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x3605 840307 bytes
SHA-256: 1b9120f56fd9230e51e69153e8274a106d6e4a8dd2cce0a344fc65dc4b2b2203
Detection
ClamAV: Win.Trojan.Agent-6943819-1
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): cmdln
embedded_office_off00006480.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x6480 828408 bytes
SHA-256: c317a4bd9958e80ca7111394bb5889fc2dd6315d3b3cb4f2cefc4e367559fdeb
Detection
ClamAV: Win.Trojan.Agent-6943819-1
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): cmdln
embedded_office_0000660a_1.exe embedded-pe Office MZ+PE at offset 0x660A 394929 bytes
SHA-256: ad52f901e40604ab3c2ca993d90bab57aae815fee5894f2ed276bfd70e9a85e6
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): cmdln
embedded_office_off00069bbd.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x69BBD 421051 bytes
SHA-256: bd2e597d24eb95a64f0a43bb9762b6b7cb4740703b538ff40730ccf59179b8e0
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): cmdln
embedded_office_off0006d1c2.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x6D1C2 407222 bytes
SHA-256: 72a4229d9057e432c8965fe069e29c3ee56a1192bb97ac4e4b8988e4f4e61b27
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered command string(s): cmdln