Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 deec7f174221d115…

MALICIOUS

Office (OLE)

36.5 KB Created: 2020-11-27 11:46:53 Authoring application: Microsoft Excel
MD5: 1dec9d4bdadeff88d755cf369c524e52 SHA-1: c4f094b9474649543392a9e2ded30c7a260e79d0 SHA-256: deec7f174221d1159bdf98ec14ec452d62d8f12659b5e3e627e60d1f1a755eed
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The file is an Excel spreadsheet containing Excel 4.0 macros, specifically an Auto_Open function. This function is known to be used for executing arbitrary code, often to download and run further malicious content. The critical heuristics indicate the presence of dangerous formula APIs within the Auto_Open macro, confirming its malicious intent. No specific URLs or hashes were extracted, but the technique strongly suggests a downloader or initial execution stage.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
886be921d11f4636042e708fd41dbc565cd4eca369a3bc493332408ceac40a16
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6730 bytes