Xls.Trojan.Kilo-1 — Office (OLE) / .XLSX malware analysis

Static analysis result for SHA-256 cc5d7b3a05d6f643…

MALICIOUS

Office (OLE) / .XLSX

27.5 KB Created: 2000-08-30 21:06:57 Authoring application: Microsoft Excel
MD5: 80289c7c3065ba7670352a6253ed0fa3 SHA-1: 244e777a8990a227e247c5c623cef27218332538 SHA-256: cc5d7b3a05d6f6437560d1d11db6fdd22caa7de6a59e493f34c19c5070834a94
180 Risk Score

Malware Insights

Xls.Trojan.Kilo-1 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The critical ClamAV heuristic indicates the file is recognized as Xls.Trojan.Kilo-1. The presence of an Auto_Open macro, which is triggered automatically when the workbook is opened, strongly suggests malicious intent. The VBA script attempts to infect the user's Excel environment by copying its macro to the PERSONAL.XLS file, which is used to store global macros. This action establishes persistence for the macro.

Heuristics 4

  • ClamAV: Xls.Trojan.Kilo-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Trojan.Kilo-1
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Auto_Open macro high OLE_VBA_AUTO
    Auto_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
8c19a542ef2baba9b15edbdfdb0c47635d0b0ca4d5d3dd44360de6cf8f87ec4f
vba-macro oletools.olevba.extract_macros (decoded VBA source) 29323 bytes
Detection
ClamAV: Xls.Trojan.Kilo-1
Obfuscation or payload: unlikely