Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 b7a919bb30c16334…

MALICIOUS

Office (OLE) / .XLS

121.0 KB Created: 2021-01-06 16:47:21 Authoring application: Microsoft Excel
MD5: cd7d4543958945e3fab4f0631e3494f3 SHA-1: 3e00f26ab9384c9c1bb24eeb2de331f751f536ed SHA-256: b7a919bb30c1633483399356aedf42c11656c8a076be969e85b57ccdd071b879
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.003 Windows Command Shell T1218 Signed Binary Proxy Execution

The file contains Excel 4.0 macros, which are known to be used for malicious purposes. Heuristics indicate suspicious invocations of cmd.exe and PowerShell, suggesting the macros are designed to execute arbitrary commands. The embedded URL likely serves as a distribution point for further malicious payloads. The presence of these elements strongly suggests a downloader or initial access attack pattern.

Heuristics 5

  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to PowerShell high SC_STR_POWERSHELL
    Reference to PowerShell
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://lankarecipes.com/Sparc.jp

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
f85bdc0d73cfdc6c468b1fd79b816c7f1240a925a8c84e67676697bfd7c3aca7
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 2760 bytes