Emotet — Office (OLE) / .XLS malware analysis

Static analysis result for SHA-256 7649a43612652c0b…

MALICIOUS

Office (OLE) / .XLS

85.0 KB Created: 2022-01-27 23:41:00 Authoring application: Microsoft Excel
MD5: e31371453defbbf8840b40b5bff8600a SHA-1: bf7b00bc9192d147adc9d2fa52c69fe796e55d67 SHA-256: 7649a43612652c0b32353e7ae9898150f885a770db0d024d0d034c4171d5d684
362 Risk Score

Malware Insights

Emotet · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample contains Excel 4.0 macros that are configured to automatically execute upon opening. The macro invokes CMD.EXE to run mshta.exe, which then downloads and executes a second-stage payload from the URL http://91.240.118.172/gg/ff/fe.html. This behavior is characteristic of Emotet downloader modules.

Heuristics 9

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • ClamAV: Xls.Downloader.Emotet-a5251d3d2d6d3722-9951020-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Emotet-a5251d3d2d6d3722-9951020-0
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to mshta.exe high SC_STR_MSHTA
    Reference to mshta.exe
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://91.240.118.172/gg/ff/fe.htmlB
    • http://91.240.118.172/gg/ff/fe.html

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
442d6b173c127aa1cacf7230e3da93b0f434b2ef7e8f05e02651142f862a415c
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 529 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 shell/COM execution token(s). Carved macro source contains an auto-exec entry point and execution/download terms.