Win.Trojan.Laroux-51 — Office (OLE) malware analysis

Static analysis result for SHA-256 fce34749482c969e…

MALICIOUS

Office (OLE)

13.5 KB Created: 1998-09-23 02:11:45 Authoring application: Microsoft Excel First seen: 2012-06-14
MD5: 4ef8ab72a9beaef05a014ed849bce8ff SHA-1: f66287fc57f48e3cad4d35e86cf76132bf9f0438 SHA-256: fce34749482c969eec3e40786020f4210ebfa66df78a9ecaac140f49de7cf182
120 Risk Score

Malware Insights

Win.Trojan.Laroux-51 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.005 Visual Basic

The file is identified as a malicious Excel 5 macro virus, specifically the Laroux family (Win.Trojan.Laroux-51). Heuristics indicate the presence of auto-execution macros like 'auto_open' and 'OnSheetActivate', suggesting it attempts to run malicious code immediately upon opening. The presence of 'laroux' markers further confirms its family. The document body is garbled, providing no additional context on its specific lure.

Heuristics 2

  • ClamAV: Win.Trojan.Laroux-51 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Laroux-51
  • Excel 5 Laroux/Larou-CV macro-virus marker cluster critical OLE_XLS5_LAROUX_MACRO_VIRUS
    Legacy Excel workbook contains a Laroux/Larou-CV macro-virus marker cluster including auto_open execution and workbook/module replication strings. This is a narrow indicator for an infected legacy Excel macro workbook.