Ldridex — Office (OLE) / .XLSX malware analysis

Static analysis result for SHA-256 a46b5d45d8ec0fd6…

MALICIOUS

Office (OLE) / .XLSX

64.0 KB Created: 2020-09-07 12:45:06 Authoring application: Microsoft Excel
MD5: 2ebf94683404817300733508c9186523 SHA-1: 6bf4999b33857a210e047fcde9b6a9cec898d695 SHA-256: a46b5d45d8ec0fd6f943d694fc9c42d7ae72d33122fb4c0e790d420c1bb53204
80 Risk Score

Malware Insights

Ldridex · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.005 Visual Basic

The file is identified as malicious by ClamAV with the signature 'Xls.Malware.Ldridex-9768648-0', strongly suggesting the Ldridex family. The presence of VBA macros, detected by a medium-severity heuristic, indicates the likely execution vector. The document body, though obfuscated, contains patterns consistent with lures used in financial scams or phishing attempts.

Heuristics 2

  • ClamAV: Xls.Malware.Ldridex-9768648-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Ldridex-9768648-0
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
df2184af9d731c8a94076667e0c0d2e52d28892695a0cdb537772719d397f326
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2634 bytes