Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 13753374c358207c…

MALICIOUS

Office (OLE)

7.0 KB First seen: 2012-06-14
MD5: b4c4ac3446774fe0573fc920762598de SHA-1: f167277d982236054fb75447851a239ba97881f1 SHA-256: 13753374c358207c0320eee14ff2fe01300ba5648fa14f283b6b99fd573fafa2
60 Risk Score

Malware Insights

The file is identified as a macro virus by ClamAV, specifically 'Win.Trojan.Spy-6'. The document body contains text that explicitly refers to it as a 'RSN MACRO VIRUS Goat file' and mentions its creator, suggesting a malicious intent to spread or infect. No specific IOCs like URLs or hashes were extracted, but the presence of macro code is a strong indicator of malicious activity.

Heuristics 1

  • ClamAV: Win.Trojan.Spy-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Spy-6