Win.Trojan.Talon-3 — Office (OLE) malware analysis

Static analysis result for SHA-256 73ebe1e67b243977…

MALICIOUS

Office (OLE)

21.5 KB Created: 1997-03-30 05:34:00 Authoring application: Microsoft Word for Windows 95 First seen: 2012-06-14
MD5: ede633036874790ff255b06bb44469c6 SHA-1: bed3d3d51e0af5685b0e23e5d6d20ea69b1a689b SHA-256: 73ebe1e67b243977aa550c29f7b6eb7d8d7e49b4546b43fb63acbcc8bdb733e7
100 Risk Score

Malware Insights

Win.Trojan.Talon-3 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The sample was detected as Win.Trojan.Talon-3, a legacy WordBasic macro virus. The extracted document body contains numerous references to macro functions and strings like 'ToolsMacro', 'Password', and 'talon3', indicating the presence and likely execution of malicious macros. The macro appears to be designed to display warning messages to the user about the document being saved by the virus.

Heuristics 2

  • ClamAV: Win.Trojan.Talon-3 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Talon-3
  • Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
    OLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.