Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 1b4af064cebc190e…

MALICIOUS

Office (OLE)

20.0 KB Created: 2002-05-08 17:23:00 Authoring application: Microsoft Word for Windows 95
MD5: 15cef289610d529beccc69d8619ebbc3 SHA-1: c76cb4088419bced026bde17b20c2c0ead2b0d04 SHA-256: 1b4af064cebc190ef5c52a9198906838a57b4537654fa38988fe74db86293d58
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is detected as Win.Trojan.Cap-1 by ClamAV, indicating it is a known malicious trojan. The document's structure and metadata suggest it is an older Office document, potentially exploiting a legacy vulnerability. No specific IOCs were extracted, but the detection strongly suggests malicious intent.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1