Win.Trojan.Onyx-1 — Office (OLE) malware analysis

Static analysis result for SHA-256 63129fec4e806b30…

MALICIOUS

Office (OLE)

25.0 KB Created: 1998-03-06 16:16:00 Authoring application: Microsoft Word for Windows 95 First seen: 2012-06-14
MD5: da1285cf22052e4306df03aed9867a0e SHA-1: 593047728b8e48c663188eb7aba52d6352990ea0 SHA-256: 63129fec4e806b30859119d9854cd6c6087b436b44eb5b505e3a5aa335c8a0cc
200 Risk Score

Malware Insights

Win.Trojan.Onyx-1 · confidence 90%

MITRE ATT&CK
T1059.003 Windows Command Shell T1566.001 Spearphishing Attachment

The file is identified as Win.Trojan.Onyx-1 by ClamAV, indicating a malicious trojan. The document body contains embedded commands and references to registry keys and batch files, such as 'Start.bat' and 'Msn.scp', suggesting a multi-stage execution. The presence of 'debug < Msn.scp' and 'debug < readme.txt' implies these files are used in the infection chain. The authoring application and creation date suggest an older malware variant.

Heuristics 3

  • ClamAV: Win.Trojan.Onyx-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Onyx-1
  • Embedded Office document has suspicious static findings critical EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE
    A CFB/OLE Office document was found inside another file type and its carved contents matched Office exploit or payload heuristics. This catches wrapped exploit documents where the top-level file routes to a PE, archive, or generic scanner instead of Office.
  • CFB header with no readable streams medium OLE_PARSE_EMPTY_STREAMS
    The file begins with a valid OLE2/CFB header but exposes no directory streams. A non-empty compound document with an unreadable directory is anomalous — it is seen with truncated/corrupt files and, more importantly, with content deliberately shifted off byte boundaries to defeat parsers while the host application still recovers the object.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_off00002f09.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x2F09 13559 bytes
SHA-256: 88d3bc8e78cefb60a7dfcb6bf0a558e96a06101b9386ebdc2d3b64ebbc445ba5
Detection
ClamAV: Win.Trojan.Onyx-1
Obfuscation or payload: unlikely