Laroux — Office (OLE) / .EXE malware analysis

Static analysis result for SHA-256 6afd606bdd32f1be…

MALICIOUS

Office (OLE) / .EXE

31.0 KB Created: 1997-12-02 15:52:50 Authoring application: Microsoft Excel
MD5: 3213932ac9d03b53f0e6987dc0af71f8 SHA-1: e373f2ed7a041db4309dc3ca5d4f254dd56d5f64 SHA-256: 6afd606bdd32f1be2ff93203cd408183de91235b5548733c25e13395b78d100a
60 Risk Score

Malware Insights

Laroux · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for OLE_XLS5_LAROUX_MACRO_VIRUS indicates the presence of the Laroux macro virus, a known threat that infects Excel workbooks. The presence of 'laroux' and 'auto_open' markers within the heuristics strongly suggests malicious macro execution upon file opening. No specific IOCs were extracted, but the family is confidently identified.

Heuristics 1

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.