Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 f414c74412b2edc5…

MALICIOUS

Office (OLE) / .XLS

30.0 KB Created: 2003-05-05 02:58:11
MD5: a903b23778d9fa8b6233f333854c1ff2 SHA-1: 8923d8e7050e0cae6c2b8b238f97821dfce33bac SHA-256: f414c74412b2edc5d8304cc5dfbbfcef2547229d7b88179cde8b5d3dffa9b60d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications

The critical heuristic 'OLE_XLS_FORMULA_MACRO_VIRUS' indicates the presence of a legacy Excel formula macro virus, specifically mentioning markers like 'Excel Formula Macro Virus', 'XF.Classic', 'Poppy by VicodinES', and 'Narkotic Network'. The document body presents a seemingly legitimate invoice or cost calculation, which is a common social engineering tactic to trick users into enabling macros. The combination of the lure document and the specific macro virus marker strongly suggests an attack pattern involving macro execution.

Heuristics 1

  • Legacy Excel formula macro virus marker critical OLE_XLS_FORMULA_MACRO_VIRUS
    Workbook stream contains self-identifying legacy Excel formula macro virus markers. This indicates the document carries formula macro virus content even when no VBA project or modern XLM macro-sheet structure is present.