Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 ba50351af8a145de…

MALICIOUS

Office (OLE)

48.5 KB Created: 1980-01-04 07:41:25 Authoring application: Microsoft Excel First seen: 2012-06-14
MD5: 6a262e4562976217be4685154f9277a7 SHA-1: bd8f7153eb4ccc36952f4cc9df00f58c40c1e82a SHA-256: ba50351af8a145de9b3ff856d0c8d87947b0779f035fca3e01cdc61020479743
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is an Excel 5 file exhibiting characteristics of the Laroux macro virus, indicated by specific marker strings and heuristic firings. The presence of these markers strongly suggests the execution of malicious VBA code, which is commonly used to download and execute further stages of malware. The ClamAV detection ID 'Legacy.Trojan.Agent-491' further supports its malicious nature.

Heuristics 2

  • ClamAV: Legacy.Trojan.Agent-491 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-491
  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.