Legacy.Trojan.Agent-476 — Office (OLE) malware analysis

Static analysis result for SHA-256 dbb9c5202e9cc3e9…

MALICIOUS

Office (OLE)

53.5 KB Created: 1998-02-25 16:38:52 Authoring application: Microsoft Excel First seen: 2012-06-14
MD5: f4deb25732b398c4fa66f72e7b2ab747 SHA-1: a9e86105ac61b06b9fe7d279750d87ebcac258be SHA-256: dbb9c5202e9cc3e9f016f2fdbce4f509c2dfcffa38254c2c9a9c3f8d9a8dd451
240 Risk Score

Malware Insights

Legacy.Trojan.Agent-476 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The file is identified as a malicious Excel 5.0 macro virus, specifically matching the 'Laroux' family markers and ClamAV's 'Legacy.Trojan.Agent-476' signature. The presence of macro virus markers like 'auto_open' and 'check_files' indicates it is designed to execute automatically upon opening. The embedded OLE structure also shows anomalies, suggesting deliberate obfuscation.

Heuristics 5

  • ClamAV: Legacy.Trojan.Agent-476 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-476
  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.
  • Embedded Office document has suspicious static findings critical EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE
    A CFB/OLE Office document was found inside another file type and its carved contents matched Office exploit or payload heuristics. This catches wrapped exploit documents where the top-level file routes to a PE, archive, or generic scanner instead of Office.
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 42,484 bytes but its declared streams total only 0 bytes — 42,484 bytes (100%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • CFB header with no readable streams medium OLE_PARSE_EMPTY_STREAMS
    The file begins with a valid OLE2/CFB header but exposes no directory streams. A non-empty compound document with an unreadable directory is anomalous — it is seen with truncated/corrupt files and, more importantly, with content deliberately shifted off byte boundaries to defeat parsers while the host application still recovers the object.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_off0000300c.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x300C 42484 bytes
SHA-256: a0292f9c1b8a86febd8a23a9a5b3755d46dcd59502978ba8b1d9dbf99c727fed