Win.Trojan.Wazzu-46 — Office (OLE) / .DOC malware analysis

Static analysis result for SHA-256 143ff5fb84d1f46e…

MALICIOUS

Office (OLE) / .DOC

14.0 KB Created: 1997-01-06 06:07:00 Authoring application: Microsoft Word for Windows 95
MD5: 81fe8a016509cc2ba83436da21da789c SHA-1: 9a3fd173bcc11cf6a6e6720c5f95b80e92dd5c85 SHA-256: 143ff5fb84d1f46e8a7de9f4763d4235b93605392e6343d0d43a0ecd62bbe831
60 Risk Score

Malware Insights

Win.Trojan.Wazzu-46 · confidence 90%

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is a malicious Word document containing a VBA macro. The heuristic firing and the presence of strings like 'Payloaddd', 'wazzu n', and 's the payloaddn' indicate that the macro is designed to execute a payload. The document body contains references to printer drivers, likely a lure to trick the user into enabling macros.

Heuristics 1

  • ClamAV: Win.Trojan.Wazzu-46 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Wazzu-46