Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 148ce8c997448f17…

MALICIOUS

Office (OLE) / .DOC

14.0 KB Created: 1996-08-14 11:31:00 Authoring application: Microsoft Word 6.0
MD5: 175dd252e4aa9810939a772e66481f4d SHA-1: fe2ffece2389e923e2ce615c6f86f82843966e53 SHA-256: 148ce8c997448f176a778d9dda32f16b29f3d7815ca7ad0e8d5ce34f6aac77e1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is identified as malicious by ClamAV with the signature Win.Trojan.Macro-11, indicating the presence of a macro. The extracted document body contains references to AUTOOPEN and file paths, suggesting a macro-based execution flow. The macro likely attempts to download and execute a secondary payload, a common tactic for malware distribution.

Heuristics 1

  • ClamAV: Win.Trojan.Macro-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Macro-11