Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 1964e1197578d3f1…

MALICIOUS

Office (OLE) / .EXE

32.0 KB Created: 1999-02-08 09:24:15 Authoring application: Microsoft Excel
MD5: 199e629c6a48ddd8a9900dd7c95d7648 SHA-1: b577d1a51fdc584ca02549878e856b4b8bc4b183 SHA-256: 1964e1197578d3f14f89972c83d52042be34faa54979b891d437288370dbf94f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified by ClamAV as 'Legacy.Trojan.Agent-494', indicating it functions as a trojan agent. The presence of 'Sophos Goat File' text and garbled characters suggests potential obfuscation or a lure. Given its classification as a trojan agent, it is highly probable that the file is designed to download and execute further malicious components.

Heuristics 1

  • ClamAV: Legacy.Trojan.Agent-494 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-494