Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 d407496a48ae88d3…

MALICIOUS

Office (OLE)

114.0 KB Created: 2004-04-22 22:56:00 Authoring application: Microsoft Word 10.0
MD5: 815bc4a375fbf4fa2f68372796a39d97 SHA-1: 1f8d7c76ee69eb58d8f9e0888540f9688ead60ba SHA-256: d407496a48ae88d3f6ad13dff03be27551ae45a41d76ac0b1a0f50f02523fd16
180 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

The file is a macro-enabled Office document detected by ClamAV as Doc.Trojan.Thus-8. The presence of a Document_Open macro indicates that malicious code will execute automatically upon opening the document. The embedded URLs are likely used to download additional malicious content. No specific family could be identified, but the overall pattern suggests a downloader.

Heuristics 5

  • ClamAV: Doc.Trojan.Thus-8 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Thus-8
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Document_Open macro high OLE_VBA_DOCOPEN
    Document_Open macro
  • VBA macros detected medium OLE_VBA_MACROS
    Document contains VBA macro code
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://onair.co.za/thetrinitysession/directorsks.htm
    • http://www.artthrob.co.za/03dec/artbio.html
    • http://www.studioxx.org

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
macros.bas
304671cd79a488b704ee3ac97dfe1b36682ff0da94733f634ee26582a59de7fb
vba-macro oletools.olevba.extract_macros (decoded VBA source) 2311 bytes
Detection
ClamAV: Doc.Trojan.Thus-8
Obfuscation or payload: unlikely