Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 e832129146628c13…

MALICIOUS

Office (OLE)

191.5 KB Created: 2002-10-30 04:02:03 Authoring application: Microsoft Excel First seen: 2015-10-13
MD5: ec1a6d0b71d8ce52171176d1a9313bb0 SHA-1: 55951db14f8e0a5aab0ece376292310ecc969d30 SHA-256: e832129146628c13cc9e2ff75bf226ccc6c00bdfb4c6deb784be1e7d5acdbd8d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample is identified as a legacy Excel formula macro virus, specifically referencing 'Poppy by VicodinES' and 'Narkotic Network'. This suggests the file is designed to execute malicious formulas or macros, likely for data theft or system compromise. The presence of these markers strongly indicates a malicious intent, although the exact payload is not discernible from the provided evidence.

Heuristics 1

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.