Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 cba79c3a8638168e…

MALICIOUS

Office (OLE) / .XLS

630.0 KB Created: 1999-03-12 07:08:30 Authoring application: Microsoft Excel
MD5: 9eb7003a4c049474a81f9ee04de0fd0a SHA-1: e507136da008cf07515024857d183c21b5b2bc52 SHA-256: cba79c3a8638168e79a6b359196b06b7f703792e04c989d40e90dac08b8c45ea
68 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications

The heuristic 'OLE_XLS_FORMULA_MACRO_VIRUS' indicates this is a legacy Excel formula macro virus, specifically mentioning 'Classic.Poppy by VicodinES' and 'XF.Classic'. The document body contains text related to invoices and payments, aligning with the 'SE_INVOICE_LURE' heuristic. The macro appears to infect the current workbook and attempt to save it, suggesting a self-propagating or spreading mechanism.

Heuristics 2

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators