Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 e788f7014a9dffed…

MALICIOUS

Office (OLE) / .XLS

94.0 KB Created: 1996-10-14 23:33:28 Authoring application: Microsoft Excel
MD5: 75e356cd9a8de08161a4bdd546fca088 SHA-1: 115c5049f7d853a714d644b4ee1daaaf98be1261 SHA-256: e788f7014a9dffed9e29f8b1c2fdd25260f467925f18e60068ef9143f6c43600
100 Risk Score

Malware Insights

The sample is an Excel spreadsheet exhibiting a critical heuristic for XOR-encoded strings with a key of 0xFC. Additionally, it shows a high heuristic for OLE slack space anomaly, indicating potential obfuscation or packed content. While no document body or scripts were extracted, the presence of encoded strings strongly suggests malicious intent, likely for delivering a secondary payload or executing arbitrary code. The confidence is moderate due to the lack of explicit script or body content to confirm the exact execution flow.

Heuristics 2

  • XOR-encoded strings (key 0xFC) critical SC_XOR_ENCODED
    Found 5 Windows library/API name(s) XOR-encoded with single-byte key 0xFC: 'kernel32.dll', 'kernel32.dll', 'LoadLibraryA', 'GetProcAddress', 'VirtualAlloc'
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 96,256 bytes but its declared streams total only 15,628 bytes — 80,628 bytes (84%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).