Win.Trojan.Formater-1 — Office (OLE) malware analysis

Static analysis result for SHA-256 751caefae0b6b7bc…

MALICIOUS

Office (OLE)

18.5 KB Created: 1998-08-21 05:22:00 Authoring application: Microsoft Word for Windows 95 First seen: 2012-06-14
MD5: 2135f9432237e8c63991e1c21b39d39c SHA-1: 09cba562f2ed0bb96127538ef625e74f1cf931a6 SHA-256: 751caefae0b6b7bc68296298e29de7a3753f94dcbec0eab8dbe497dc691aedce
100 Risk Score

Malware Insights

Win.Trojan.Formater-1 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The sample was detected as Win.Trojan.Formater-1, a legacy WordBasic macro virus. Heuristics indicate the presence of macro virus markers and specific macro names like AutoExec and AutoOpen, suggesting the macro is designed to execute automatically upon opening the document. The document body contains strings related to the 'Formater' virus and mentions 'win.ini', indicating potential system modification or persistence attempts.

Heuristics 2

  • ClamAV: Win.Trojan.Formater-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Formater-1
  • Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
    OLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.