Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 202bd2774bafc7c5…

MALICIOUS

Office (OLE)

29.0 KB Created: 1999-08-11 18:55:00 Authoring application: Microsoft Word 8.0
MD5: 5c6de0fcf183c520e11bf2d7bbe0bf7f SHA-1: c6e385376f1132994a4e6b7897a6faf554bcb2a2 SHA-256: 202bd2774bafc7c5c8faf315da7e3204f07249696a832ff7793b331222f030de
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a Microsoft Word document containing VBA macros, identified by ClamAV as Doc.Trojan.Ethan-20. The document body presents a petition against banking practices, requesting personal information such as name, address, and signature, likely for fraudulent purposes. No scripts were extracted, but the presence of macros and the document's content suggest a social engineering lure for data harvesting.

Heuristics 3

  • ClamAV: Doc.Trojan.Ethan-20 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Ethan-20
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
95bd068ab5d8893918d8686523abfe9059acbeb203bc3b9a2fc5b4157e65112a
vba-macro oletools.olevba.extract_macros (decoded VBA source) 6272 bytes
Detection
ClamAV: Doc.Trojan.Ethan-1
Obfuscation or payload: unlikely