Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 7c0d514764c153a6…

MALICIOUS

Office (OLE) / .XLS

2.28 MB Created: 2012-08-26 11:32:03 Authoring application: Microsoft Excel First seen: 2026-04-20
MD5: 60c6d2ca134d03b2f11167b19e52760c SHA-1: 1c5d0a6035de3ce79fe21e7161fe4a115aa4f807 SHA-256: 7c0d514764c153a67eb33e38ca6e168240dd11e9efa576bf3643b423939ae7a3
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1566.002 Spearphishing Attachment

The file contains VBA macros, specifically a Workbook_Open macro, which is a common technique for malicious documents. The document body presents a form for user data entry, disguised as a student registration or insurance package selection. The Workbook_Open macro appears to control worksheet protection and visibility, likely to facilitate the user interaction with the form. While the embedded URL is marked as benign, the overall structure and macro execution strongly suggest a phishing or social engineering attempt to collect user information.

Heuristics 3

  • Workbook_Open macro high OLE_VBA_WBOPEN
    Workbook_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.google.hu/#hl=hu&gs_rn=2&gs_ri=hp&tok=UREv0pm354CVYhfzmttHAQ&cp=49&gs_id=2x&xhr=t&q=speichern+als+excel+vba+die+Datei+schon+existiert&es_nrs=true&pf=p&tbo=d&sclient=psy-ab&oq=speichern+als+excel+vba+die+Datei+schon+existiert&gs_l=&pbx=1&bav=on.2,or.r_gc.r_pw.r_qf.&bvm=bv.42080656,d.d2k&fp=7b4d55219b90e571&biw=1024&bih=581

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
5ce9992d4778cb40e77191571374029db33d21fc27b2280091b054bbfff23dbf
vba-macro oletools.olevba.extract_macros (decoded VBA source) 70469 bytes