Xls.Dropper.Agent-7659640-0 — Office (OLE) / .XLS malware analysis

Static analysis result for SHA-256 6d85a763dcae8ad9…

MALICIOUS

Office (OLE) / .XLS

59.0 KB Created: 2020-04-07 09:48:49 Authoring application: Microsoft Excel
MD5: 0fe98300fc311d5db5b4612d86385b15 SHA-1: 89784a86f239738db0307cbf684dcc7259a74358 SHA-256: 6d85a763dcae8ad9c21bace54e2657f3a326793c287c0ad0188ecaa2309f162a
280 Risk Score

Malware Insights

Xls.Dropper.Agent-7659640-0 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristics indicate the presence of VBA macros that utilize WScript.Shell to execute commands. The VBA script contains a function that appears to construct and execute a command, likely for downloading and running a secondary payload. The ClamAV detection name further supports its classification as a dropper.

Heuristics 6

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • WScript.Shell usage critical OLE_VBA_WSCRIPT
    WScript.Shell usage
  • ClamAV: Xls.Dropper.Agent-7659640-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.Agent-7659640-0
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
c55c640dea6229d89e3d05372ba4b930a9ff67c0899325f8b604a9ef9cef4251
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1711 bytes