Win.Trojan.Pesan-2 — Office (OLE) malware analysis

Static analysis result for SHA-256 502b51fb4a4f9f08…

MALICIOUS

Office (OLE)

9.0 KB First seen: 2012-06-14
MD5: 573b053befcbd8ef3148706c3c934791 SHA-1: 1eec65f4a040f97627d4b2343f71093c5ffed4c6 SHA-256: 502b51fb4a4f9f08e013fc19cb7e6f25adc58deca4f2871423ba7b6b5e3416d9
100 Risk Score

Malware Insights

Win.Trojan.Pesan-2 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The sample exhibits characteristics of a legacy macro virus, specifically identified as a 'RSN MACRO VIRUS Goat file'. ClamAV detection confirms it as Win.Trojan.Pesan-2. The presence of legacy macro virus markers and the file's description strongly indicate its purpose is to execute malicious routines, likely through the embedded macro, which falls under the Visual Basic technique.

Heuristics 2

  • ClamAV: Win.Trojan.Pesan-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Pesan-2
  • Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
    OLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.