MALICIOUS
60
Risk Score
Malware Insights
MITRE ATT&CK
T1059.005 Visual Basic
The critical heuristic firing for OLE_XLS_FORMULA_MACRO_VIRUS, along with the embedded text referencing "Excel Formula Macro Virus", "Poppy by VicodinES", and "The Narkotic Network 1998", strongly suggests this is a macro-based threat. The file appears to be designed to infect other Excel workbooks by copying itself into the XLSTART directory, potentially leading to widespread infection or further payload delivery.
Heuristics 1
-
Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUSWorkbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.
Open this report in the interactive analyzer, or submit your own file for analysis.