Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 aafa44d762b0647a…

MALICIOUS

Office (OLE) / .XLS

32.5 KB Created: 2007-10-24 21:06:51 Authoring application: Microsoft Excel
MD5: 552683ed83f2d56a7fe9047a5c207ba3 SHA-1: a51488b1188f2da6cac36333e2949b4a4515ac8c SHA-256: aafa44d762b0647a8cd1973382ec84ca948f905f6ec1f805d5670f098668f273
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1566.002 Spearphishing Attachment

The file is an Excel spreadsheet containing VBA macros, specifically an Auto_Open macro, which is a common technique for executing malicious code upon opening. The ClamAV detection 'Doc.Macro.Laroux-5893719-0' strongly indicates malicious intent. The document body presents a list of computer hardware specifications, likely a lure to trick the user into enabling macros. The Auto_Open macro suggests the intent is to download and execute a second-stage payload.

Heuristics 3

  • ClamAV: Doc.Macro.Laroux-5893719-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Laroux-5893719-0
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
b35f884f1ab3c6e6c1dbe2d6db716dba0e1ebba6f7c888a0fd88da628484a892
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1912 bytes