Malicious Office (OLE) / .XLS — malware analysis report

Static analysis result for SHA-256 fc4d47b0ab4c8fde…

MALICIOUS

Office (OLE) / .XLS

4.91 MB
MD5: e8e2f53fa6803e3b0edddacb7ca9ebea SHA-1: 3cf205a4668726518361c6fb8c6bc45d39e9b4fc SHA-256: fc4d47b0ab4c8fde8f5a27d31bb65235fe4e084b97d7c8f18ace4262a15f2aa8
80 Risk Score

Malware Insights

MITRE ATT&CK
T1059 Command and Scripting Interpreter T1059.001 Command and Scripting Interpreter: PowerShell T1218 System Binary Proxy Execution T1218.011 System Binary Proxy Execution: Rundll32

The file is an XLS document containing references to legitimate corporate reports, likely as a lure. Heuristics indicate the presence of Windows Script Host and visible LOLBin command execution, suggesting the document attempts to execute a script. The embedded URLs, while appearing legitimate, may be used to download or host malicious content. The specific techniques observed point towards command and script interpreter usage, potentially involving PowerShell or similar execution tools.

Heuristics 3

  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.metlife.com.mx/wps/portal/seguros/!ut/p/c1/04_SB8K8xLLM9MSSzPy8xBz9CP0os3hHtyDjAG93QwN3Cz8DAyM_NzOzMAN_Y_9gE_1wkA6cKtxNDSHyHqbuYd4geX8gNDAyDwJiXw9Dd1eovAEO4Gig7-eRn5uqX5CdHWThqKgIABb2x2w!/dl2/d1/L2dJQSEvUUt3QS9ZQnB3LzZfQUZSM1BLRzEwRzhOMDAyTkY2NlYwTzNPQTI!/�
    • http://www.compartamos.com/wps/wcm/connect/?MOD=PDMProxy&TYPE=personalization&ID=NONE&KEY=NONE&LIBRARY=%2FcontentRoot%2Ficm%3Alibraries&FOLDER=%2FRelacion+con+Inversionistas%2FInformacion+Financiera%2FInforme+Anual%2FInforme+Anual+En%2F&DOC_NAME=%2FcontentRoot%2Ficm%3Alibraries%2FRelacion+con+Inversionistas%2FInformacion+Financiera%2FInforme+Anual%2FInforme+Anual+En%2FAnnual+Report+Compartamos+Banco+08.pdf&VERSION_NAME=NONE&VERSION_DATE=NONE&IGNORE_CACHE=false&CONVERT=text/html&MUST_CONVERT=fals
    • http://www.biffa.co.uk/pdfs/enviroreport2000_1.pdf2
    • http://www.biffa.co.uk/pdfs/enviroreport2000_2.pdf4
    • http://www.carillionplc.co.uk/sustain/f_con2.htm=
    • http://www.carillionplc.com/assets/downloads/pdfs/envirpt.pdf
    • http://www.transalta.com/transalta/webcms.nsf/AllDoc/A6E5FABF729C196987257157004F9A4D/$File/1999SDReport.pdf
    • https://www.vancity.com/SharedContent/documents/2592_1998socialreport.pdf
    • http://www.btplc.com/Societyandenvironment/PDF/2001/DownloadthesectionasPDFdocument.htm
    • http://www.endesa.es/Portal/en/our_commitment/sustainability_3/8_reports_publications/default.htm
    • http://www.inco.com/development/reports/ehs/2001/executive/default.asp
    • http://www.kesko.fi/index.asp?id=C473A9A1731E42EA86F5CC8539ECA0FE
    • http://www.loyyangpower.com.au/(
    • http://www.musgrave.ie/px/CSRPDFs/Environmental2002.pdf2
    • http://www.tdk.co.jp/csr_e/kankyo_e/report/report01/index.htm
    • http://www.wrg.co.uk/data/downloads/she2000.pdf
    • http://www.btplc.com/Societyandenvironment/PDF/2002/Downloads2002.htm
    • http://www.chiquita.com/content/chiquitacr01/default.asp
    • http://www.codelco.com/desarrollo/reporte/reporte_2001.pdf�
    • http://www.coillte.ie/about_coillte/publications/annual_reports/2002_reports/social_and_environmental_report_2002/
    • http://www.danisco.com/cms/connect/corporate/about%20danisco/sustainability/sustainability%20reports/2002%20performance/sustainability_report_perf2002_en.htm
    • http://www.landcareresearch.co.nz/publications/annualreport_0102/pdf/AR2002_sect1.pdf
    • http://www.landcareresearch.co.nz/publications/annualreport_0102/pdf/AR2002_sect2.pdf
    • http://www.newcrest.com.au//upload/2005%20Sustainability%20Report%20-%20Summary.pdf
    • http://www.nikeresponsibility.com/pdfs/color/Nike_FY01_CR_report.pdf�
    • http://www.sabmiller.com/files/reports/2002_sd_report.pdf0
    • http://www.tallpoppies.co.nz/documents/TBL_Tall_Poppies.pdf
    • http://www.tdk.co.jp/csr_e/kankyo_e/report/report02/index.htmB
    • http://www.tdk.co.jp/csr_e/kankyo_e/report/kankyo_02e/index_e.html
    • http://www.transalta.com/transalta/webcms.nsf/AllDoc/387C305AA9EFD5E48725723A0067A8B1/$File/TransAlta2001RS.pdf
    • http://www.transalta.com/sd2001/index.htm
    • https://www.vancity.com/SharedContent/documents/2000-01AccountabilityReport.pdf
    • http://www.wisconsinenergy.com/performrpt/pdf/wec_performancereport_2001.pdf3
    • http://www.wisconsinenergy.com/performrpt/index.htm
    • http://www.aceaspa.it/acea/acea_eng/ambiente_societa/bilancio/bilancio_2002.html
    • http://www.arcandor.com/de/downloads/bericht_nachhaltigkeit_2003_d.pdf
    • http://www.btplc.com/Societyandenvironment/PDF/2003/index.htm
    • http://www.coca-colahbc.hr/uploads/20050707192120Socijalno_Izvjesce.pdf
    • http://www.codelco.com/desarrollo/reporte/reporte_2002.pdf(
    • http://www.furukawa.co.jp/enviro/english/env2003/enviro_rpt2003.htm
    • http://portal.gasnatural.com/servlet/ContentServer?gnpage=3-10-1&centralassetname=3-10-BloqueHTML-9800
    • http://www.gdfsuez.com/fileadmin/user_upload/pdf/rdd_gdf_2002.pdf
    • http://www.holcim.com.br/gc/BR/uploads/Relatorio%20Holcim%202003%20.pdf
    • http://www.indesitcompany.com/pages/it/finance/financialReportsView.do?year=2002
    • http://www.kutxa.net/wkn_entidadfinanciera_new/es/responsabilidad_social/responsabilidad_gestion.htm�
    • http://www.lafarge.fr/LafargeAlternative/Publication/en/09222004-publication_sustainable-Sustainability_report_2002_051503-uk/index.htm
    • http://www.magyartelekom.hu/docs/kornyezetvedelmi_jelentes_2002_en.pdfO
    • http://www.landcareresearch.co.nz/publications/annualreport_0203/pdf/AR2003.pdf
    • http://natura.infoinvest.com.br/enu/648/Eng_Annual_Report_2003.pdf$
    • http://www.posco.com/homepage/docs/eng/jsp/sustain/report/s91d7050020l.jsp&
    +2885 more URL(s)