Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 dcd58ab1376dc9e2…

MALICIOUS

Office (OLE)

970.0 KB Created: 2003-07-26 08:11:40 Authoring application: Microsoft Excel First seen: 2015-09-24
MD5: 6a85b3c80e9a67b41b203c6752d898c0 SHA-1: b8988ffba2fb73d4b7f26ef1a59f7ec685e1901e SHA-256: dcd58ab1376dc9e2509b6d1612b6a7cae34feab58b8e79b46dec3ed4dd0ffb22
82 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The critical heuristic firing for 'OLE_XLS_FORMULA_MACRO_VIRUS' and the medium heuristic for 'OLE_XLM_AUTOOPEN' indicate the presence of legacy Excel macros. The document body contains construction-related text, likely a lure. The presence of these macros strongly suggests the file's intent is to execute malicious code, likely a downloader, leveraging the XLM macro capabilities.

Heuristics 3

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.� In document text (OLE body)
    • http://ns.adobe.com/xap/1.0/In document text (OLE body)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In document text (OLE body)
    • http://ns.adobe.com/exif/1.0/In document text (OLE body)
    • http://ns.adobe.com/pdf/1.3/In document text (OLE body)
    • http://ns.adobe.com/photoshop/1.0/In document text (OLE body)
    • http://ns.adobe.com/tiff/1.0/In document text (OLE body)
    • http://ns.adobe.com/xap/1.0/mm/In document text (OLE body)
    • http://purl.org/dc/elements/1.1/In document text (OLE body)