Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 b1047e68886b72c4…

MALICIOUS

Office (OLE) / .XLS

179.0 KB Created: 2020-07-01 23:17:53 Authoring application: Microsoft Excel
MD5: 3dd2345a9ee5a36a834d97b4cd6176db SHA-1: 7212f6050eb564e319ffad8dec1f6e626407d038 SHA-256: b1047e68886b72c47a5186f4a5125936fb483b3d106cf7e10d80c762ba66f494
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1059.001 PowerShell T1564.002 Hidden Window

The sample contains Excel 4.0 (XLM) macros, specifically an Auto_Open function, which is a known technique for executing malicious code. The heuristics indicate the presence of dangerous formula APIs and environment evasion techniques within the macro. While no specific URLs or hashes were extracted, the Auto_Open macro itself is the primary indicator of malicious intent, likely to download and execute a second-stage payload.

Heuristics 4

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • XLM Auto_Open environment-evasion close gate critical OLE_XLM_ENVIRONMENT_EVASION_CLOSE
    Excel 4.0 macro sheet auto-executes environment checks with GET.WORKSPACE / GET.WINDOW, then shows a fake corruption/error message and closes the workbook when the host fails those checks. This is a malware sandbox-evasion pattern, even when the later payload stage is hidden behind obfuscated defined-name flow.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
287437003fdcd3648346c4fcc46cbb78572db84e057baeb44e25a6b0e9084078
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 58782 bytes