Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 f9c4abfb87149d52…

MALICIOUS

Office (OLE) / .XLS

104.6 KB Created: 1996-12-17 01:32:42 Authoring application: Microsoft Excel
MD5: ce9f98bc1b7359e0a4853f682cf7fdc7 SHA-1: 1cd51db0eacda297a977c14f61732008f2f8f17c SHA-256: f9c4abfb87149d5228712b1f069f5e38faa59576b9af133665f7a314f9f6acc7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell

The sample is an OLE Excel file with a large amount of slack space, indicating potential obfuscation or embedded content. A high-severity heuristic detected a suspicious invocation of cmd.exe with an execution flag, suggesting command execution. Another heuristic noted PEB access, often used by malware to evade detection. While no scripts were extracted, the combination of these indicators points to an attempt to download and execute a second-stage payload.

Heuristics 4

  • PEB access via FS segment (x86) high SC_PEB_ACCESS
    PEB access via FS segment (x86)
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • OLE document has large unaccounted-for region high OLE_SLACK_ANOMALY
    OLE file is 107,070 bytes but its declared streams total only 24,565 bytes — 82,505 bytes (77%) live in unallocated sector slack. This is the canonical hiding place for pre-macro-era Office exploit payloads (XOR-encoded shellcode reached via a parser pointer-corruption bug in the document structure).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.pdf-repair.com
    • http://www.pdf-repair.com)/Producer(Advanced
    • http://www.pdf-repair.com)/ModDate(D:20100406171120+08
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/