Win.Trojan.Makrone-1 — Office (OLE) malware analysis

Static analysis result for SHA-256 9875ba4dc5a1517d…

MALICIOUS

Office (OLE)

6.0 KB First seen: 2012-06-14
MD5: cd7157651a9f78e28f363fae21f2cdd5 SHA-1: bde83e361b9f2a1e92a5889983a735c6709a1f67 SHA-256: 9875ba4dc5a1517d22b5ae3612ced0a9cb8b18126b414217d63bf23c38f13cd1
100 Risk Score

Malware Insights

Win.Trojan.Makrone-1 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The sample exhibits characteristics of a legacy macro virus, specifically identified as a 'RSN MACRO VIRUS Goat file' and detected by ClamAV as Win.Trojan.Makrone-1. The presence of legacy WordBasic macro virus markers and the explicit mention of 'RSN MACRO VIRUS' in the document body strongly suggest the execution of malicious macro code upon opening.

Heuristics 2

  • ClamAV: Win.Trojan.Makrone-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Makrone-1
  • Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
    OLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.