Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 6927917bd4544095…

MALICIOUS

Office (OLE) / .XLS

115.5 KB Created: 2008-11-03 07:28:09 Authoring application: Microsoft Excel
MD5: 7cfaecfed657130c4fd15f5a9ce8cc10 SHA-1: a068e3c441c39e73f0465a30d2cc1794874ec112 SHA-256: 6927917bd45440953a6b5aa3b97737acb061b77871dc3f74807ed9cb70c7291a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic 'OLE_XLS_FORMULA_MACRO_VIRUS' and the presence of 'Excel Formula Macro Virus', 'Poppy by VicodinES', and 'The Narkotic Network' in the document body strongly indicate a legacy Excel macro virus. The document body also contains instructions for infecting and saving a workbook as 'Book1.xls', suggesting a propagation mechanism. No specific family could be identified.

Heuristics 1

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.