Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 820647a4cdef012c…

MALICIOUS

Office (OLE)

40.0 KB Created: 2005-01-15 13:45:00 Authoring application: Microsoft Word 10.1
MD5: a6dc38c277b43d5479386b565b6388cc SHA-1: b62eb1f28b72a355a441554e29441b5988037f94 SHA-256: 820647a4cdef012ce9f265200479ab25698860bce40bf0aa09a8c68aef6cf129
180 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The sample contains a critical ClamAV detection for 'Doc.Trojan.Thus-8', indicating malicious content. A high-severity heuristic confirms the presence of a 'Document_Open' VBA macro, which is designed to execute automatically when the document is opened. This macro likely attempts to ensure its own persistence and potentially download additional malicious content, as suggested by the heuristic 'OLE_VBA_MACROS'.

Heuristics 4

  • ClamAV: Doc.Trojan.Thus-8 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Thus-8
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
a5c6a312d435fbe0dbbdb44a7eb4b8ca28801dadc0b47266138cf2d5f32abe40
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2364 bytes
Detection
ClamAV: Doc.Trojan.Thus-8
Obfuscation or payload: unlikely