Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 a715cc46445b1729…

MALICIOUS

Office (OLE) / .XLS

107.0 KB Created: 1996-12-17 01:32:42 Authoring application: Microsoft Excel
MD5: efd9db52d8d90b24e91d5ac0e31020ee SHA-1: e2ddbb8101b25b0fdb06af8640c02b6a12e11c99 SHA-256: a715cc46445b1729e198260b85fccdef2836f307183c6ca01334aca8a0b75bea
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The OLE document exhibits anomalies indicative of malicious intent, including a large slack region and an appended executable payload. While VBA macros could not be extracted due to an unsupported format, the presence of an appended payload suggests the file is designed to download and execute a second-stage payload. The file path 'C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE' was found in the document structure, potentially indicating a target or a component of the attack.

Heuristics 3

  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 109,592 bytes but its declared streams total only 24,565 bytes — 85,027 bytes (78%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • OLE file has appended executable-looking payload bytes high OLE_APPENDED_PAYLOAD
    OLE compound file contains a large high-entropy region beyond the declared major streams and that region includes shellcode, PE, or loader API markers. This is a payload-carrier signal, not a specific CVE attribution by itself.
  • Unsupported Office format for VBA extraction info OFFICE_FORMAT_UNSUPPORTED
    olevba could not extract VBA macros (PermissionError); format-agnostic byte-level scans still ran. Likely legacy, encrypted, or malformed OLE/OOXML — re-scanning the same bytes will yield the same outcome.