Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 696bc799c2d49036…

MALICIOUS

Office (OLE)

36.0 KB Created: 2020-11-27 11:42:42 Authoring application: Microsoft Excel
MD5: 73e12116792e9dd871c5c7763e9572a7 SHA-1: 4454a5123eac0ce7bb528f536d96cea39b7b8a15 SHA-256: 696bc799c2d49036b8ecca8b479da0b04aac10022f03cce9014007c24ea45a43
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristics indicate the presence of Excel 4.0 macros with an Auto_Open defined name and dangerous formula APIs, specifically the RUN function. This strongly suggests the macro is designed to execute arbitrary code upon opening the document. While no specific URLs or hashes were extracted, the presence of these dangerous functions points to a downloader or initial execution stage for a malicious payload.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
276aa5a8d5268e9824762bdc9d9d0d0b76042f3d77e7b39525c86607a14d31cd
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6791 bytes