Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 1d70466cd94c9814…

MALICIOUS

Office (OLE)

278.0 KB Created: 2008-08-25 01:32:00 Authoring application: Microsoft Word 11.5.0
MD5: 78672c10c89467eb5f93e1a93bd9c94b SHA-1: f51223df6537227acb4dcec1d14ddd5c071b26e9 SHA-256: 1d70466cd94c981410209cfc672c7981dec325e53b1aab43a46e8a0121e9d688
120 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Doc.Trojan.Walker-9. Static analysis detected the presence of VBA macros, specifically a Document_Open macro, indicating an attempt to automatically execute malicious code upon opening the document. The document body content is presented as an educational assignment, likely a lure to encourage user interaction and macro execution. No specific malware family could be confidently identified.

Heuristics 4

  • ClamAV: Doc.Trojan.Walker-9 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Walker-9
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.iowaaeaonline.org/
    • http://www.cotf.edu/ete/modules/msese/earthsysflr/plates2.html
    • http://www.calendarsthatwork.com/membershipd.php
    • http://www.windows.ucar.edu/
    • http://pds.jpl.nasa.gov/planets/
    • http://pubs.usgs.gov/gip/dynamic/understanding.html
    • http://www.apple.com/DTDs/PropertyList-1.0.dtd

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
28881cc02edbe5fa3d44379f155ed27f6b47492861bc9c6070ff8d8b8914261a
vba-macro oletools.olevba.extract_macros (decoded VBA source) 3158 bytes