Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 e80cd5eec1117111…

MALICIOUS

Office (OLE)

36.0 KB Created: 2020-11-25 10:37:03 Authoring application: Microsoft Excel
MD5: a020675731afaa412eead402e329039e SHA-1: 5c960cdbe8f1d7f98a65f115a4684a6784c5116c SHA-256: e80cd5eec1117111be4f8df40aa74f602c5e13cfae1b33b1e2e2c511b8b4885a
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1203 Exploitation for Client Execution

The critical heuristics indicate the presence of Excel 4.0 macros with an Auto_Open function, which is a known method for executing malicious code. The macro sheet contains a reference to 'Auto_Open', suggesting it will run automatically when the workbook is opened. The presence of dangerous formula APIs like RUN further supports the malicious intent. The document body contains heavily obfuscated text, which is typical for macro-based malware attempting to hide its true payload or purpose.

Heuristics 3

  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt
98e345e72aab2fd86b7f596a931e010c386184a836ec07094e0ee752964ff3af
xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 6564 bytes