Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 0a0a8741d182c37f…

MALICIOUS

Office (OLE)

66.5 KB Created: 2009-01-07 18:26:00 Authoring application: Microsoft Word 11.3.5
MD5: 83e650037bad05d4ac159faf3f1c7373 SHA-1: fd3c90a500e118b99a4b222026491449c50a7be2 SHA-256: 0a0a8741d182c37fabc687db9e838f0dc5440eb28c7ce3798a90bf689fa2db0e
122 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1547.001 Registry Run Keys / Startup Folder

The sample contains a VBA macro triggered by the Document_Open event, which is designed to copy itself into the Normal.dot template and the active document. This technique is commonly used to ensure persistence and facilitate the execution of malicious code across multiple documents. The macro explicitly disables virus protection and attempts to inoculate both the document and the Normal template, indicating a clear intent to spread.

Heuristics 4

  • ClamAV: Doc.Trojan.Marker-35 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Marker-35
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.realtokyo.co.jp/english/column/ozaki97.htm
    • http://www.eu-japanfest.org/english/program/12/lille/flower.html
    • http://www.creativtv.net/v2/06/biennalyon.html
    • http://www.arttowermito.or.jp/art/zero.html
    • http://www.kirin.co.jp/active/art/kpo/art/exhibitions/2003/tabadeki_1.html
    • http://dazed.excite.co.jp/dazed_people/art/deki_yayoi/
    • http://www.findarticles.com/p/articles/mi_m0NTN/is_50/ai_111506869
    • http://metropolis.japantoday.com/tokyo/536/art.asp

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
f5002f7cabdb72007a507ea4a68dfb172e6f199556c3c2b08e39298247953581
vba-macro oletools.olevba.extract_macros (decoded VBA source) 1590 bytes