Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 9a2f4f787e230f0e…

MALICIOUS

Office (OLE) / .XLS

1.03 MB Created: 2006-09-16 00:00:00 Authoring application: Microsoft Excel
MD5: 33f48496bc3dec2447e83c21a5cb3c67 SHA-1: caa22548451f7bcdffae0b2e557b81d2032f342b SHA-256: 9a2f4f787e230f0e3008b547be3d5d46f42e8d0763b736f77e953c90ea0ce2bb
68 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.005 Visual Basic

The critical heuristic firing indicates exploitation of CVE-2017-0199 via an OLE2Link object, which is designed to load remote content. The embedded URL 'https://getabre.com/VAI8YW' is the likely source for this remote payload. Although the VBA project is small and contains no executable statements, the OLE vulnerability itself is sufficient for initial compromise. The file is an Excel spreadsheet, suggesting a social engineering lure to open the document.

Heuristics 3

  • OLE2Link / URL Moniker → remote loader — CVE-2017-0199 critical CVE likely CVE_2017_0199
    Document contains an embedded OLE link object whose URL Moniker points to a remote URL. When the host file is opened, Office follows the link, downloads the URL, and processes the response based on its Content-Type (HTA -> mshta.exe, RTF → Word, etc.) — the documented CVE-2017-0199 primitive. The URL extension is not a reliable filter; servers can return different payloads to Office's user agent.
  • VBA project contains no executable statements low OLE_VBA_MACROS
    Document contains a VBA project, but extracted modules only contain attributes/options/comments and no executable statements.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/drawingml/2006/main
    • http://schemas.microsoft.com/office/2006/metadata/longProperties
    • http://schemas.openxmlformats.org/officeDocument/2006/customXml
    • http://schemas.microsoft.com/office/2006/metadata/contentType
    • http://schemas.microsoft.com/office/2006/metadata/properties/metaAttributes
    • http://schemas.microsoft.com/office/2006/metadata/properties
    • http://www.w3.org/2001/XMLSchema
    • http://schemas.microsoft.com/sharepoint/v3
    • http://schemas.microsoft.com/office/2006/documentManagement/types
    • http://schemas.openxmlformats.org/package/2006/metadata/core-properties
    • http://www.w3.org/2001/XMLSchema-instance
    • http://purl.org/dc/elements/1.1/
    • http://purl.org/dc/terms/
    • http://schemas.microsoft.com/office/internal/2005/internalDocumentation
    • http://dublincore.org/schemas/xmls/qdc/2003/04/02/dc.xsd
    • http://dublincore.org/schemas/xmls/qdc/2003/04/02/dcterms.xsd

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
0bedd32ea8c7bec8ef74cc8e5bea59e33d01f9a02d0a98c97ddecca9bc6aa980
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1812 bytes