Doc.Trojan.Thus-10 — Office (OLE) malware analysis

Static analysis result for SHA-256 18482533ee935807…

MALICIOUS

Office (OLE)

88.0 KB Created: 2008-02-01 13:42:00 Authoring application: Microsoft Word 11.2
MD5: a155be9222eb14d3109b067ec7f1f02e SHA-1: 8f2e89a76cd45d661443d5a1a66fbd90350de54f SHA-256: 18482533ee935807fe339c44b6be3c7662c75e1afa53d5437df8527dddea9723
182 Risk Score

Malware Insights

Doc.Trojan.Thus-10 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1547.001 Registry Run Keys / Startup Folder

The sample is identified as malicious by ClamAV with the signature Doc.Trojan.Thus-10. It contains a Document_Open VBA macro that attempts to copy itself to the Normal.dot template, likely to achieve persistence and spread to other documents. The macro also attempts to disable virus protection and manipulate VBProject components, indicating malicious intent.

Heuristics 5

  • ClamAV: Doc.Trojan.Thus-10 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Thus-10
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.apple.com/DTDs/PropertyList-1.0.dtd

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
3401ade9fbd7c7b92ab94836d153315a614afdc96916824f47ab833b7a9bd896
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2257 bytes
Detection
ClamAV: Doc.Trojan.Thus-10
Obfuscation or payload: unlikely