Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 761c9ec3ed25e98e…

MALICIOUS

Office (OLE) / .XLS

185.0 KB Created: 2020-07-01 23:17:53 Authoring application: Microsoft Excel
MD5: 6829d18ce97cb75313c275ae90b5d068 SHA-1: 9405702686663df6a96d8da8aa1cb8cae86e34bc SHA-256: 761c9ec3ed25e98ed2337494d92a68f0feb6679ef6aedf0b4dc47e1407651b2b
220 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The sample is an Excel file containing Excel 4.0 macros, specifically an Auto_Open function. This function is designed to execute automatically when the workbook is opened, and the heuristics indicate it uses dangerous formula APIs and environment evasion techniques. The presence of an Auto_Open macro strongly suggests the intent is to download and execute a second-stage payload, a common tactic for initial compromise via spearphishing attachments.

Heuristics 5

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • XLM Auto_Open environment-evasion close gate critical OLE_XLM_ENVIRONMENT_EVASION_CLOSE
    Excel 4.0 macro sheet auto-executes environment checks with GET.WORKSPACE / GET.WINDOW, then shows a fake corruption/error message and closes the workbook when the host fails those checks. This is a malware sandbox-evasion pattern, even when the later payload stage is hidden behind obfuscated defined-name flow.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
c829d04a30932320020774e42e65d4196f494b0006e9ef77723f205c9369cb62
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 64408 bytes