Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 d6620ebd295b9dd8…

MALICIOUS

Office (OLE) / .XLS

1.92 MB Created: 2000-05-26 16:45:09 Authoring application: Microsoft Excel
MD5: e36d115a09f4bdfdd800154d5232e6c8 SHA-1: c132b3020765e5a7509af0039612976a2054b46a SHA-256: d6620ebd295b9dd84a4af1cee393b6c306a822e38798eeb0cfe04fcc83ae7ab0
200 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications T1059.001 PowerShell

The file is identified as malicious due to critical heuristic firings indicating the presence of legacy Excel 4.0 (XLM) Auto_Open macros and a legacy XLM macro-virus family marker 'XL4Poppy'. While VBA macros are also detected, the primary threat appears to stem from the older XLM macro functionality. The document body contains what appears to be Vietnamese construction cost estimation data, which is likely a lure. No specific IOCs like URLs or hashes were extracted, but the presence of XLM macros is a strong indicator of malicious intent.

Heuristics 4

  • Excel 4.0 (XLM) Auto_Open + macro sheet critical OLE_XLM_AUTOOPEN
    Workbook contains an Auto_Open / Auto_Close defined name together with an Excel 4.0 macro sheet — the canonical XLM auto-execution shape used by malware families such as Emotet and QakBot.
  • Legacy XLM macro-virus family marker critical OLE_XLM_LEGACY_MACRO_VIRUS
    Workbook contains an Excel 4.0 macro Auto_Open chain and legacy macro-virus family strings. This is a narrow indicator for infected XLM workbooks rather than ordinary formula use.
  • ClamAV: Xls.Malware.Generic-6680536-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Generic-6680536-0
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
666058ae70451137942d0df27d6aaad533470bccf4ffd0fa9cd050d499d7d411
vba-macro oletools.olevba.extract_macros (decoded VBA source) 8732 bytes