Xls.Trojan.Laroux-3 — Office (OLE) / .EXE malware analysis

Static analysis result for SHA-256 61f21e8d94a7348d…

MALICIOUS

Office (OLE) / .EXE

53.0 KB Created: 1999-02-08 09:24:15 Authoring application: Microsoft Excel
MD5: 1048ca50595ff75e94e21130b88879ea SHA-1: 42db9a87f2bf66c690c463b9ae69c97bd12f589a SHA-256: 61f21e8d94a7348de2300719b4fe200c435b65865f56ccd62ffcf623efd6e6c3
180 Risk Score

Malware Insights

Xls.Trojan.Laroux-3 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is identified as a malicious Excel 5 macro virus, specifically the Laroux-CV variant, by multiple critical heuristics and ClamAV. The auto_open macro is designed to execute a function named 'check_files' upon opening the document, which then attempts to save a file named 'KKKKK.XLS' in the startup path. This suggests a downloader or dropper functionality, likely intended to fetch and execute a secondary payload.

Heuristics 4

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
1141860579c621ebab4f4694c179d344891ec07450d70b9bebb5c04bf04d38bf
vba-macro oletools.olevba.extract_macros (decoded VBA source) 3762 bytes
Detection
ClamAV: Xls.Trojan.Laroux-3
Obfuscation or payload: unlikely