Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 e77a0f6b3b33d4cf…

MALICIOUS

Office (OLE) / .XLS

1.16 MB Created: 2002-08-05 03:52:27 Authoring application: Microsoft Excel
MD5: 7907ab38a53e4dc365c7ec67d51b7f97 SHA-1: fc926980ac3330711df4aac4f7c8d5f1f46e0c64 SHA-256: e77a0f6b3b33d4cf1116f394eb9db6b4c21f6c148ce90e5b4460a25929322c08
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications

The critical heuristic firing indicates this is a legacy Excel formula macro virus, specifically identified as 'Classic.Poppy by VicodinES' and 'XF.Classic' from 'The Narkotic Network'. The document body contains embedded strings and comments confirming its nature as a macro virus that infects other workbooks, saving them as 'Book1.xls'.

Heuristics 1

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.