Xls.Downloader.b83ac4c497e169b5-9980307-0 — Office (OLE) / .XLS malware analysis

Static analysis result for SHA-256 88c2ada3a44e94b4…

MALICIOUS

Office (OLE) / .XLS

74.0 KB Created: 2022-11-29 07:16:03 First seen: 2022-11-30
MD5: df47927080bdfe099b7f0c92eedbb7b5 SHA-1: f5c53a6652a1d1542b95ec87e66569b90f3831fc SHA-256: 88c2ada3a44e94b4f055996a517a0db92fd66c9060e60280857071e6ac23f159
188 Risk Score

Malware Insights

Xls.Downloader.b83ac4c497e169b5-9980307-0 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1105 Ingress Tool Transfer

The critical heuristic OLE_VBA_SHELL indicates the presence of shell execution capabilities within the VBA macros. The HTML_PDF function within the script attempts to download content from a provided URL using MSXML2.XMLHTTP, suggesting it acts as a downloader for a second-stage payload. The ClamAV detection further confirms its malicious nature as a downloader.

Heuristics 5

  • Shell() call in VBA critical OLE_VBA_SHELL
    Shell() call in VBA
  • ClamAV: Xls.Downloader.b83ac4c497e169b5-9980307-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.b83ac4c497e169b5-9980307-0
  • CreateObject call high OLE_VBA_CREATEOBJ
    CreateObject call
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Environ() call (env variable access) low OLE_VBA_ENVIRON
    Environ() call (env variable access)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
eb48ca61505819a4d99cc693d2dd3c25fbe1407842f37a3b8b364fd8c22ae10c
vba-macro oletools.olevba.extract_macros (decoded VBA source) 5069 bytes