Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 57e7769beca541f5…

MALICIOUS

Office (OLE) / .XLS

616.5 KB Created: 2009-12-24 06:52:45 Authoring application: Microsoft Excel First seen: 2026-05-10
MD5: 7b02802a52d6e5f216df58d6921072b6 SHA-1: 3b5b40a13b38117c0155be55ecbf0b33ff596bc5 SHA-256: 57e7769beca541f557dbd6d5f8c82d5850af1f87204097fb5e421f6bb3897e0c
80 Risk Score

Heuristics 2

  • Legacy XLM macro-virus family marker critical OLE_XLM_LEGACY_MACRO_VIRUS
    Workbook contains an Excel 4.0 macro sheet and legacy macro-virus family or workbook-replication strings. This is a narrow indicator for infected XLM workbooks rather than ordinary formula use.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.