Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 ad4c5f91571cbc62…

MALICIOUS

Office (OLE)

15.5 KB Created: 1997-03-06 23:16:00 Authoring application: Microsoft Word for Windows 95 First seen: 2012-06-14
MD5: 4c6b439795bd4b857bb45f15aef31301 SHA-1: da03747f858108805bb9d70d84b5b01c74479ccd SHA-256: ad4c5f91571cbc62923d2484f871a1600e97a694ec96eaf748fe08a7259d94fc
180 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The sample contains legacy WordBasic macro virus markers and a document body explicitly describing itself as a 'wordmacro virus' named 'DarkSide1B'. The macro aims to spread itself and disable security features like 'ToolsMacro' and 'FileTemplate'. The embedded URLs and email address are likely associated with the malware author or distribution infrastructure.

Heuristics 4

  • ClamAV: Win.Trojan.Dark-5 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Dark-5
  • Embedded Office document has suspicious static findings critical EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE
    A CFB/OLE Office document was found inside another file type and its carved contents matched Office exploit or payload heuristics. This catches wrapped exploit documents where the top-level file routes to a PE, archive, or generic scanner instead of Office.
  • Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
    OLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.
  • CFB header with no readable streams medium OLE_PARSE_EMPTY_STREAMS
    This finding applies to a carved embedded Office document found at a nonzero offset inside the submitted file, not directly to the top-level document. The file begins with a valid OLE2/CFB header but exposes no directory streams. A non-empty compound document with an unreadable directory is anomalous — it is seen with truncated/corrupt files and, more importantly, with content deliberately shifted off byte boundaries to defeat parsers while the host application still recovers the object.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_office_off00001488.ole embedded-office Embedded OLE/CFB Office body inside ole container at offset 0x1488 10616 bytes
SHA-256: 232f2de9dfc01b7d46874c1cf13e4805831d850be1e7ab43e5fd37484c08025d