Win.Trojan.Nuker-11 — Office (OLE) malware analysis

Static analysis result for SHA-256 d58c3626cff49135…

MALICIOUS

Office (OLE)

21.0 KB First seen: 2012-06-14
MD5: 8dfd243ae20ec07438bfbcbe00a2d530 SHA-1: f9c392576ef7e0a76c83f5422460886d156919ed SHA-256: d58c3626cff491351843494bdf4c93afb0c5d71364d78966708675ba41146fe4
100 Risk Score

Malware Insights

Win.Trojan.Nuker-11 · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic

The sample exhibits characteristics of a legacy macro virus, specifically identified by the 'RSN MACRO VIRUS Goat file' markers and the 'Win.Trojan.Nuker-11' ClamAV detection. The document body contains numerous references to 'NuclearPower' and various AutoExec functions, suggesting an attempt to execute malicious code upon opening or interacting with the document.

Heuristics 2

  • ClamAV: Win.Trojan.Nuker-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Nuker-11
  • Legacy WordBasic macro-virus markers high OLE_LEGACY_WORDBASIC_MACRO_VIRUS
    OLE Word document contains legacy WordBasic auto-execution macro markers such as AutoOpen plus ToolsMacro/MacroFile/fileMacro/globMacro or named historical macro-virus strings. These old Word 6/95 macro forms are not exposed as a modern VBA project, so normal VBA source extraction can miss them.