Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 e0af5a7c9d4c60b9…

MALICIOUS

Office (OLE) / .XLS

24.5 KB Created: 2020-11-03 06:51:17 Authoring application: Microsoft Excel
MD5: fd69b945de0ab3947508d0855a853463 SHA-1: 5d81b0cdc3a1c875207b1ffc54f982f876ba0592 SHA-256: e0af5a7c9d4c60b999390ffa3298f94c6051df5f419ce48d5b0657358b4dd084
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.003 Windows Command Shell T1218 System Binary Proxy Execution

The presence of Excel 4.0 macros (OLE_XLM_AUTOOPEN) and suspicious command-line invocations (SC_STR_CMD, SC_STR_POWERSHELL, SE_LOLBIN_RUN_COMMAND) indicates the file is designed to execute arbitrary commands. The embedded URL 'http://magigal.co' is likely used to download and execute a secondary payload. The confidence is high due to the clear indicators of malicious macro execution.

Heuristics 5

  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to PowerShell high SC_STR_POWERSHELL
    Reference to PowerShell
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://magigal.co

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
65c56f1893f65f2eb6e184788c470d1106fe429146f74db9f68697a514f68c5a
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 1107 bytes