Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 09c10bf958b66d2d…

MALICIOUS

Office (OLE)

393.0 KB Created: 1998-04-14 03:38:00 Authoring application: Microsoft Word for Windows 95
MD5: 0f9a886d10ab70ddb28df96e317f6264 SHA-1: cfaf6c5610149e97dbb439bc0d68ee811c063921 SHA-256: 09c10bf958b66d2d470974b4182d596ba7ff6e4d65cd29e8ab45a4cf34d60ab6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file is an OLE document created with Microsoft Word 95, a version known to be vulnerable to various exploits. The CLAMAV_DETECTION heuristic firing for 'Win.Trojan.Tm-1' strongly suggests the presence of malicious code. The document body contains unusual strings and keywords like 'AUTOOPEN' which may indicate macro execution or exploit attempts.

Heuristics 1

  • ClamAV: Win.Trojan.Tm-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Tm-1