Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 16299c547e40db5a…

MALICIOUS

Office (OLE)

35.0 KB Created: 2010-05-06 09:56:00 Authoring application: Microsoft Word 11.3.8
MD5: b53f9d952979805f1415acb826ef6205 SHA-1: ebd9367c25a363eb1d1cace82b1560b066dc9545 SHA-256: 16299c547e40db5af811a121352fecad41ba189e025e5c5d76f04393075cc4b8
220 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature 'Doc.Trojan.Thus-8'. It contains a VBA macro that is triggered by the 'Document_Open' event, indicating an attempt to execute malicious code upon opening. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may be part of a social engineering scheme to trick users into providing passwords for archives, often used to bypass security scanning.

Heuristics 5

  • ClamAV: Doc.Trojan.Thus-8 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Thus-8
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
e4d31dc6d9d6b73474253c4f4e8bc86783e4d30175a0876b9ad06b847c84a1e1
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2350 bytes
Detection
ClamAV: Doc.Trojan.Thus-8
Obfuscation or payload: unlikely