Xls.Dropper.Agent-7763650-0 — Office (OLE) / .DOC malware analysis

Static analysis result for SHA-256 83153f8f77280dad…

MALICIOUS

Office (OLE) / .DOC

241.0 KB Created: 2020-04-17 06:37:08 Authoring application: Microsoft Excel
MD5: e7853f2c88f4b8d1b6177750d5c209b6 SHA-1: 3bdf1281d67269a3eb84b6845f1f4e6c1b8ea337 SHA-256: 83153f8f77280dad3afc5198da15f8a94d29ccca4883ea89f41529e52a4c99fa
120 Risk Score

Malware Insights

Xls.Dropper.Agent-7763650-0 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

The file is identified as malicious by ClamAV with the signature Xls.Dropper.Agent-7763650-0. Static analysis revealed the presence of Excel 4.0 (XLM) macros, specifically an Auto_Open macro that utilizes dangerous function APIs, including the RUN function. This strongly suggests the macro is designed to download and execute a secondary payload. The embedded URLs are confirmed benign and do not appear to be directly involved in the malicious execution.

Heuristics 4

  • ClamAV: Xls.Dropper.Agent-7763650-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.Agent-7763650-0
  • XLM Auto_Open with dangerous formula APIs high OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.microsoft.com/photo/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
b4f92c28ce613ff09c05c3f26c2c24a0f6dfd9499693c8c98d57cf49a8e5a6af
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 140278 bytes