Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 c878cb833086d8ce…

MALICIOUS

Office (OLE)

13.0 KB Created: 1997-01-01 04:07:14 Authoring application: Microsoft Excel First seen: 2012-06-14
MD5: af11776a9e9b6069368860b0e8f54300 SHA-1: 50f3967fcd0a8b242fb5df4c16b161dde9259968 SHA-256: c878cb833086d8cebebae2bd6a0b383e62eb3d64111efbf9ad91f03a3f74ce55
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Xls.Trojan.Legend-1, indicating it is a known Excel-based threat. The document body contains garbled text, suggesting potential obfuscation or corruption, but the primary indicator is the ClamAV detection, pointing towards a malicious Excel file likely delivered via spearphishing.

Heuristics 1

  • ClamAV: Xls.Trojan.Legend-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Trojan.Legend-1