Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 c8170238e833c277…

MALICIOUS

Office (OLE) / .EXE

39.5 KB Created: 1980-01-05 19:23:25 Authoring application: Microsoft Excel
MD5: e8c34740758fa4d7e65758a0c45918a3 SHA-1: e15eb8ec549d11efbf5ea7c1ec15309017268f6c SHA-256: c8170238e833c27790bda0364999a4364010dc3974fae5a2a59980896a363e27
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified by ClamAV as Xls.Dropper.Agent-1560309, indicating it functions as a dropper. The presence of garbled text in the document body, along with the 'laroux variant' comment, suggests a potential attempt to obfuscate or disguise the malicious content. The primary function appears to be downloading and executing additional malware.

Heuristics 1

  • ClamAV: Xls.Dropper.Agent-1560309 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.Agent-1560309