🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 295fd997fff27d84839e01a87ab308f71dc37b56757ff3139c66ee22e70ec76e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Maldoc score: 43


Intelligence 11 IOCs YARA 11 File information Comments

SHA256 hash: 295fd997fff27d84839e01a87ab308f71dc37b56757ff3139c66ee22e70ec76e
SHA3-384 hash: 9ccc95972060f44431fcb3b045329ccda4a194029e3252fd884065a2dd0a05df9a8b3cdd7a7c696f2f16a958e01d0f97
SHA1 hash: cb11289d047db3087408a741f05ee0283cf420b2
MD5 hash: 3b2d339436af476adb10fd7a41f57483
humanhash: social-mango-bluebird-lamp
File name:Pre arrival Kiel Canal.xls
Download: download sample
File size:1'956'352 bytes
First seen:2026-09-12 13:05:15 UTC
Last seen:Never
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 24576:b93uqqNjpQ3uOXMo96m+Q7ynR4J74CWh9vF2a:Nuv9o9+Q7yn
TLSH T15095D642F72AC667C2585A354DDBC7A47730BD06AE46570330C9BB3E3DF7A90AE01689
TrID 34.9% (.XLS) Microsoft Excel sheet (32500/1/3)
30.1% (.XLS) Microsoft Excel sheet (alternate) (28000/1/3)
26.3% (.XLS) Microsoft Excel sheet (alternate) (24500/1/2)
8.6% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika xls
Reporter abuse_ch
Tags:xls

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 43
Application name is Microsoft Excel
Author of this document is Brunet
File Format is MS Excel 97-2003
Container Format is OLE
Office document contains VBA Macros
OLE dump

MalwareBazaar was able to identify 146 sections in this file using oledump:

Section IDSection sizeSection name
1108 bytesCompObj
2916 bytesDocumentSummaryInformation
3240 bytesSummaryInformation
4175395 bytesCtls
5704442 bytesWorkbook
62406 bytes_VBA_PROJECT_CUR/PROJECT
71013 bytes_VBA_PROJECT_CUR/PROJECTwm
83841 bytes_VBA_PROJECT_CUR/VBA/DieseArbeitsmappe
93008 bytes_VBA_PROJECT_CUR/VBA/Klasse1
1053279 bytes_VBA_PROJECT_CUR/VBA/Modul1
112614 bytes_VBA_PROJECT_CUR/VBA/Modul2
124604 bytes_VBA_PROJECT_CUR/VBA/Modul3
132500 bytes_VBA_PROJECT_CUR/VBA/Tabelle01
1423658 bytes_VBA_PROJECT_CUR/VBA/Tabelle02
1518469 bytes_VBA_PROJECT_CUR/VBA/Tabelle03
1625670 bytes_VBA_PROJECT_CUR/VBA/Tabelle04
1713771 bytes_VBA_PROJECT_CUR/VBA/Tabelle05
1813593 bytes_VBA_PROJECT_CUR/VBA/Tabelle06
1915311 bytes_VBA_PROJECT_CUR/VBA/Tabelle07
2028431 bytes_VBA_PROJECT_CUR/VBA/Tabelle08
2135101 bytes_VBA_PROJECT_CUR/VBA/Tabelle09
2216400 bytes_VBA_PROJECT_CUR/VBA/Tabelle10
2319393 bytes_VBA_PROJECT_CUR/VBA/Tabelle11
2415831 bytes_VBA_PROJECT_CUR/VBA/Tabelle12
2522451 bytes_VBA_PROJECT_CUR/VBA/Tabelle13
2622537 bytes_VBA_PROJECT_CUR/VBA/Tabelle14
2724358 bytes_VBA_PROJECT_CUR/VBA/Tabelle15
2824660 bytes_VBA_PROJECT_CUR/VBA/Tabelle16
299943 bytes_VBA_PROJECT_CUR/VBA/Tabelle17
3012383 bytes_VBA_PROJECT_CUR/VBA/Tabelle18
3112448 bytes_VBA_PROJECT_CUR/VBA/Tabelle19
321183 bytes_VBA_PROJECT_CUR/VBA/Tabelle21
3318119 bytes_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
3436488 bytes_VBA_PROJECT_CUR/VBA/__SRP_0
354925 bytes_VBA_PROJECT_CUR/VBA/__SRP_1
361568 bytes_VBA_PROJECT_CUR/VBA/__SRP_10
37312 bytes_VBA_PROJECT_CUR/VBA/__SRP_11
3818775 bytes_VBA_PROJECT_CUR/VBA/__SRP_12
391564 bytes_VBA_PROJECT_CUR/VBA/__SRP_13
4019875 bytes_VBA_PROJECT_CUR/VBA/__SRP_14
411202 bytes_VBA_PROJECT_CUR/VBA/__SRP_15
4224639 bytes_VBA_PROJECT_CUR/VBA/__SRP_16
432260 bytes_VBA_PROJECT_CUR/VBA/__SRP_17
442194 bytes_VBA_PROJECT_CUR/VBA/__SRP_18
45306 bytes_VBA_PROJECT_CUR/VBA/__SRP_19
4613719 bytes_VBA_PROJECT_CUR/VBA/__SRP_1a
47960 bytes_VBA_PROJECT_CUR/VBA/__SRP_1b
4813895 bytes_VBA_PROJECT_CUR/VBA/__SRP_1c
491012 bytes_VBA_PROJECT_CUR/VBA/__SRP_1d
5013915 bytes_VBA_PROJECT_CUR/VBA/__SRP_1e
511318 bytes_VBA_PROJECT_CUR/VBA/__SRP_1f
522060 bytes_VBA_PROJECT_CUR/VBA/__SRP_2
5327067 bytes_VBA_PROJECT_CUR/VBA/__SRP_20
542958 bytes_VBA_PROJECT_CUR/VBA/__SRP_21
5532901 bytes_VBA_PROJECT_CUR/VBA/__SRP_22
564380 bytes_VBA_PROJECT_CUR/VBA/__SRP_23
5713363 bytes_VBA_PROJECT_CUR/VBA/__SRP_24
581294 bytes_VBA_PROJECT_CUR/VBA/__SRP_25
5923135 bytes_VBA_PROJECT_CUR/VBA/__SRP_26
60804 bytes_VBA_PROJECT_CUR/VBA/__SRP_27
6112151 bytes_VBA_PROJECT_CUR/VBA/__SRP_28
621626 bytes_VBA_PROJECT_CUR/VBA/__SRP_29
6317047 bytes_VBA_PROJECT_CUR/VBA/__SRP_2a
642132 bytes_VBA_PROJECT_CUR/VBA/__SRP_2b
6517433 bytes_VBA_PROJECT_CUR/VBA/__SRP_2c
662132 bytes_VBA_PROJECT_CUR/VBA/__SRP_2d
6719999 bytes_VBA_PROJECT_CUR/VBA/__SRP_2e
682406 bytes_VBA_PROJECT_CUR/VBA/__SRP_2f
69284 bytes_VBA_PROJECT_CUR/VBA/__SRP_3
7020199 bytes_VBA_PROJECT_CUR/VBA/__SRP_30
712406 bytes_VBA_PROJECT_CUR/VBA/__SRP_31
726617 bytes_VBA_PROJECT_CUR/VBA/__SRP_32
731048 bytes_VBA_PROJECT_CUR/VBA/__SRP_33
7411057 bytes_VBA_PROJECT_CUR/VBA/__SRP_34
75960 bytes_VBA_PROJECT_CUR/VBA/__SRP_35
7610909 bytes_VBA_PROJECT_CUR/VBA/__SRP_36
77960 bytes_VBA_PROJECT_CUR/VBA/__SRP_37
78464 bytes_VBA_PROJECT_CUR/VBA/__SRP_38
79106 bytes_VBA_PROJECT_CUR/VBA/__SRP_39
80357 bytes_VBA_PROJECT_CUR/VBA/__SRP_3a
81440 bytes_VBA_PROJECT_CUR/VBA/__SRP_3b
82269 bytes_VBA_PROJECT_CUR/VBA/__SRP_3c
83326 bytes_VBA_PROJECT_CUR/VBA/__SRP_3d
8428113 bytes_VBA_PROJECT_CUR/VBA/__SRP_4
851278 bytes_VBA_PROJECT_CUR/VBA/__SRP_5
861162 bytes_VBA_PROJECT_CUR/VBA/__SRP_6
87480 bytes_VBA_PROJECT_CUR/VBA/__SRP_7
881710 bytes_VBA_PROJECT_CUR/VBA/__SRP_8
89500 bytes_VBA_PROJECT_CUR/VBA/__SRP_9
902269 bytes_VBA_PROJECT_CUR/VBA/__SRP_a
91630 bytes_VBA_PROJECT_CUR/VBA/__SRP_b
921710 bytes_VBA_PROJECT_CUR/VBA/__SRP_c
93500 bytes_VBA_PROJECT_CUR/VBA/__SRP_d
941498 bytes_VBA_PROJECT_CUR/VBA/__SRP_e
95450 bytes_VBA_PROJECT_CUR/VBA/__SRP_f
961955 bytes_VBA_PROJECT_CUR/VBA/dir
9710368 bytes_VBA_PROJECT_CUR/VBA/frmCalendar1
983870 bytes_VBA_PROJECT_CUR/VBA/frmCountryName
992435 bytes_VBA_PROJECT_CUR/VBA/frmError
1007202 bytes_VBA_PROJECT_CUR/VBA/frmF1
1013739 bytes_VBA_PROJECT_CUR/VBA/frmNSTCode
1023671 bytes_VBA_PROJECT_CUR/VBA/frmPurposeOfCall
1033176 bytes_VBA_PROJECT_CUR/VBA/frmShiptype
10477955 bytes_VBA_PROJECT_CUR/VBA/frmXML
10597 bytes_VBA_PROJECT_CUR/frmCalendar1/CompObj
106296 bytes_VBA_PROJECT_CUR/frmCalendar1/VBFrame
1073323 bytes_VBA_PROJECT_CUR/frmCalendar1/f
1085670 bytes_VBA_PROJECT_CUR/frmCalendar1/o
10997 bytes_VBA_PROJECT_CUR/frmCountryName/CompObj
110301 bytes_VBA_PROJECT_CUR/frmCountryName/VBFrame
111163 bytes_VBA_PROJECT_CUR/frmCountryName/f
112115 bytes_VBA_PROJECT_CUR/frmCountryName/i04/CompObj
113176 bytes_VBA_PROJECT_CUR/frmCountryName/i04/f
114110 bytes_VBA_PROJECT_CUR/frmCountryName/i04/i06/CompObj
115108 bytes_VBA_PROJECT_CUR/frmCountryName/i04/i06/f
11696 bytes_VBA_PROJECT_CUR/frmCountryName/i04/i06/o
117110 bytes_VBA_PROJECT_CUR/frmCountryName/i04/i07/CompObj
118108 bytes_VBA_PROJECT_CUR/frmCountryName/i04/i07/f
11996 bytes_VBA_PROJECT_CUR/frmCountryName/i04/i07/o
120148 bytes_VBA_PROJECT_CUR/frmCountryName/i04/o
12148 bytes_VBA_PROJECT_CUR/frmCountryName/i04/x
1220 bytes_VBA_PROJECT_CUR/frmCountryName/o
12397 bytes_VBA_PROJECT_CUR/frmError/CompObj
124288 bytes_VBA_PROJECT_CUR/frmError/VBFrame
125415 bytes_VBA_PROJECT_CUR/frmError/f
126468 bytes_VBA_PROJECT_CUR/frmError/o
12797 bytes_VBA_PROJECT_CUR/frmF1/CompObj
128280 bytes_VBA_PROJECT_CUR/frmF1/VBFrame
129147 bytes_VBA_PROJECT_CUR/frmF1/f
13096 bytes_VBA_PROJECT_CUR/frmF1/o
13197 bytes_VBA_PROJECT_CUR/frmNSTCode/CompObj
132293 bytes_VBA_PROJECT_CUR/frmNSTCode/VBFrame
133159 bytes_VBA_PROJECT_CUR/frmNSTCode/f
13496 bytes_VBA_PROJECT_CUR/frmNSTCode/o
13597 bytes_VBA_PROJECT_CUR/frmPurposeOfCall/CompObj
136306 bytes_VBA_PROJECT_CUR/frmPurposeOfCall/VBFrame
137159 bytes_VBA_PROJECT_CUR/frmPurposeOfCall/f
13896 bytes_VBA_PROJECT_CUR/frmPurposeOfCall/o
13997 bytes_VBA_PROJECT_CUR/frmShipType/CompObj
140294 bytes_VBA_PROJECT_CUR/frmShipType/VBFrame
141159 bytes_VBA_PROJECT_CUR/frmShipType/f
14296 bytes_VBA_PROJECT_CUR/frmShipType/o
14397 bytes_VBA_PROJECT_CUR/frmXML/CompObj
144290 bytes_VBA_PROJECT_CUR/frmXML/VBFrame
145195 bytes_VBA_PROJECT_CUR/frmXML/f
146104 bytes_VBA_PROJECT_CUR/frmXML/o
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecWorkbook_OpenRuns when the Excel Workbook is opened
AutoExecWorkbook_BeforeCloseRuns when the Excel Workbook is closed
AutoExecCheckBox1_GotFocusRuns when the file is opened and ActiveXobjects trigger events
AutoExecCommandButton2_ClickRuns when the file is opened and ActiveXobjects trigger events
AutoExeccboM_ChangeRuns when the file is opened and ActiveXobjects trigger events
AutoExecUserForm_ResizeRuns when the file is opened and ActiveXobjects trigger events
Base64HDUSERV
IOChttp://www.w3.org/2001/XMLSchemaURL
IOChttp://e-declaration.dakosy.de/EdiMessagesURL
Stringcode and P-code are different, this may havebeen used to hide malicious code
SuspiciousOpenMay open a file
SuspiciousWriteMay write to a file (if combined with Open)
SuspiciousPutMay write to a file (if combined with Open)
SuspiciousOutputMay write to a file (if combined with Open)
SuspiciousBinaryMay read or write a binary file (if combinedwith Open)
SuspiciousFileCopyMay copy a file
SuspiciousCopyHereMay copy a file
SuspiciousKillMay delete a file
SuspiciousShellMay run an executable file or a systemcommand
SuspiciousMkDirMay create a directory
SuspiciousCreateObjectMay create an OLE object
SuspiciousShell.ApplicationMay run an application (if combined withCreateObject)
SuspiciousChrMay attempt to obfuscate specific strings(use option --deobf to deobfuscate)
SuspiciousXorMay attempt to obfuscate specific strings(use option --deobf to deobfuscate)
SuspiciousHex StringsHex-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)
SuspiciousBase64 StringsBase64-encoded strings were detected, may beused to obfuscate strings (option --decode tosee all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
xls
Verdict:
Malicious activity
Analysis date:
2026-09-12 13:09:32 UTC
Tags:
macros macros-on-open

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/vnd.ms-excel
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
macros macros-on-open
Label:
Benign
Suspicious Score:
/10
Score Malicious:
%
Score Benign:
1%
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Document contains an embedded VBA with many string operations indicating source code obfuscation
Document contains VBA stomped code (only p-code) potentially bypassing AV detection
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
6 match(es)
Tags:
ATT&CK T1564.007 Blacklist VBA COM Behavior Trace DeObfuscated Malicious Malicious Document Obfuscated Office Document SOS: 0.30 SOS: 0.31 SOS: 0.32 SOS: 0.33 SOS: 0.34 SOS: 0.35 SOS: 0.36 SOS: 0.38 SOS: 0.41 SOS: 0.42 SOS: 0.43 SOS: 0.44 SOS: 0.45 SOS: 0.46 SOS: 0.47 SOS: 0.48 SOS: 0.50 T1027 T1059.005 VBA Stomping VBScript
Threat name:
Document-Excel.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-12 13:06:33 UTC
File Type:
Document
Extracted files:
211
AV detection:
4 of 23 (17.39%)
Threat level:
  2/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:TA505_Maldoc_21Nov_2
Author:Arkbird_SOLG
Description:invitation (1).xls
Reference:https://twitter.com/58_158_177_102/status/1197432303057637377
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments