AgentTesla — Office (OLE) / .XLS malware analysis

Static analysis result for SHA-256 6301c7185aeb51cc…

MALICIOUS

Office (OLE) / .XLS

31.5 KB Created: 2023-01-25 09:53:00 Authoring application: Microsoft Excel First seen: 2023-01-25
MD5: 3518e0ea1d12fb7270840ccf51ea7e12 SHA-1: e90eaadc59e9c50c0d8a263ad3f5b919c4cf9105 SHA-256: 6301c7185aeb51cc2bf3eb5840b1af2a6491dc9447628e7b371e8639a62bf64f
222 Risk Score

Malware Insights

AgentTesla · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1059.003 Windows Command Shell T1105 Ingress Tool Transfer

The critical heuristic OLE_VBA_SHELL indicates the presence of a Shell() call within the VBA macros. The Auto_Open macro is present and executes this Shell() call. The script decodes a PowerShell command that downloads a file from 'https://filebin.net/ivlin4mef64u7wuk7/nodeffender.exe' and saves it as 'Order.exe', then executes it. This indicates the sample acts as a downloader for a second-stage payload, consistent with AgentTesla.

Heuristics 6

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • ClamAV: Win.Dropper.AgentTesla-9969002-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Dropper.AgentTesla-9969002-0
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA p-code auto-exec with execution tokens high OLE_VBA_PCODE_AUTOEXEC_EXEC
    Compiled VBA/cache stream contains an auto-execution token together with shell/download/object-execution tokens. This catches p-code-only or source-extraction-failure macro documents where visible source is unavailable.
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
9774feed3fe4d8300b980d9bdda2554eaa5e3e1609fe9b9be2dd8bcee5af199b
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1441 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).