Ldridex — Office (OOXML) / .XLSM malware analysis

Static analysis result for SHA-256 9852a64ff8dd64e9…

MALICIOUS

Office (OOXML) / .XLSM

30.7 KB Created: 2020-09-30 12:03:43 UTC Authoring application: Microsoft Excel 16.0300
MD5: 155c990dfb8e9456d6b44f3c01a3699b SHA-1: b3e46cd16f750440b8b3ac2eaec082417bd1c97d SHA-256: 9852a64ff8dd64e99326dc917c70b9b68c1e80128260035fdae275bf5fc66972
140 Risk Score

Malware Insights

Ldridex · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1566.002 Spearphishing Attachment

The file is an XLSM document, and the presence of VBA macros is confirmed by heuristics. ClamAV detection explicitly identifies the file as 'Xls.Malware.Ldridex-9769692-0', strongly suggesting the Ldridex family. The obfuscated document body content likely serves as a lure to encourage macro execution, a common tactic for Ldridex to download and execute further payloads.

Heuristics 3

  • ClamAV: Xls.Malware.Ldridex-9769692-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Ldridex-9769692-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • VBA project inside OOXML medium OOXML_VBA
    Document contains vbaProject.bin — VBA macros present

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
afc0743d4e2d09e4079ae892acfc05e9da23a2b8f736520c0e2241415143da98
vba-macro oletools.olevba.extract_macros (decoded VBA source from OOXML) 2549 bytes
vbaProject_00.bin
7b31b6529df8233d6ae0e341da0c665490b6eb3d7c71143c50703d06b483b4bf
vba-project OOXML VBA project: xl/vbaProject.bin 22016 bytes
Detection
ClamAV: Xls.Malware.Ldridex-9769692-0
Obfuscation or payload: unlikely
emf_00.emf
53a88b00b3c0368a97f07e5705cf02259ed019efd03221a3f484b750c1f9742f
ooxml-emf OOXML EMF part: xl/media/image1.emf 1408 bytes