Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 70ca6c4b2400061b…

MALICIOUS

Office (OLE) / .EXE

17.5 KB Created: 1995-08-04 21:06:38 Authoring application: Microsoft Excel
MD5: 42f678efc252ad57cae6d61bd4fd9bb7 SHA-1: 900df15f152c79436320068f002288b3ebf2cf5a SHA-256: 70ca6c4b2400061b6d17586bd24a9aa3565e6d788e113482f15728f4e4498932
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for OLE_XLS5_LAROUX_MACRO_VIRUS strongly indicates the presence of the Laroux macro virus within this Excel 5 file. This family is known for its ability to spread and infect other Excel workbooks, often through auto-execution routines like 'auto_open'. The presence of multiple macro-related markers further supports this classification.

Heuristics 1

  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.