Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 9d569f1d4282195e…

MALICIOUS

Office (OLE)

30.5 KB Created: 1980-01-05 19:26:37 Authoring application: Microsoft Excel First seen: 2012-06-14
MD5: 204519aa71dd5d9fb07c887d9ee9af48 SHA-1: 373b75099307cbb214512c7034a8f73986218181 SHA-256: 9d569f1d4282195ee16fa708a5fbd71e06e7fa9d4c8be1673b5dc153061a6f71
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.005 Visual Basic

The sample is an Excel file exhibiting markers associated with the Laroux macro virus, a known legacy threat. ClamAV also detects it as a legacy trojan agent. The presence of macro virus markers strongly indicates that the file is intended to execute malicious Visual Basic for Applications (VBA) code when opened, likely as part of a phishing campaign.

Heuristics 2

  • ClamAV: Legacy.Trojan.Agent-34819 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-34819
  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.