Excel/Laroux-M — Office (OLE) / .EXE malware analysis

Static analysis result for SHA-256 6aa55c15ba0b9ea7…

MALICIOUS

Office (OLE) / .EXE

26.5 KB Created: 1997-10-16 17:41:22 Authoring application: Microsoft Excel
MD5: 5a8994ddce855bbe61ca361fb9ce5f58 SHA-1: 2dbfcc080c2e8db8db2ef1dc05811824cf218757 SHA-256: 6aa55c15ba0b9ea7d9488616c6e94fd428dbd87ecf100d304a187741a063ddc9
60 Risk Score

Malware Insights

Excel/Laroux-M · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for OLE_XLS5_LAROUX_MACRO_VIRUS clearly indicates the presence of the Excel Laroux macro virus. The document body confirms this, explicitly stating 'This file is infected with Excel/Laroux-M'. The virus is known for its self-replication and potential to carry out other malicious activities.

Heuristics 1

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.