Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 1cdbaffc21d237c0…

MALICIOUS

Office (OLE) / .DOC

24.0 KB Created: 1986-05-06 10:26:00 Authoring application: Microsoft Word 6.0
MD5: 5a46421a926283befd6243a2ad940718 SHA-1: cfacc5488ae32356094e97ccfd7d96f2ab16902c SHA-256: 1cdbaffc21d237c0fc17f2c39fca84e5e790100e913afe009d25c05cb479a0d8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is a Microsoft Word 6.0 document with a detected ClamAV signature of Win.Trojan.Macro-11. The document body contains strings that appear to be related to macro execution, including 'AUTOOPEN', and references to 'Epson Stylus Pro XL' and a fake filename 'B:\WUC\W1.DOC', suggesting a social engineering lure to enable macros. No scripts were extracted, and no specific IOCs were identified beyond the file itself.

Heuristics 1

  • ClamAV: Win.Trojan.Macro-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Macro-11