Malicious Office (OLE) / .DOT — malware analysis report

Static analysis result for SHA-256 1d0bc621847de671…

MALICIOUS

Office (OLE) / .DOT

11.5 KB Created: 1997-08-22 01:35:00 Authoring application: Microsoft Word for Windows 95
MD5: 806e40d81ee6cad44ef96fbd138d07a3 SHA-1: ea0fae7ba5ad6aa6cab240781acabc9585662af9 SHA-256: 1d0bc621847de67114b3f851461952de7dddeb9686efdefd875e470ac187be4a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified by ClamAV as 'Doc.Dropper.Agent-5354692-0', indicating it functions as a dropper. The document body contains seemingly random text and paths, which is common in obfuscated malicious documents. No scripts were extracted, but the ClamAV detection strongly suggests the file's purpose is to download and execute a malicious payload.

Heuristics 1

  • ClamAV: Doc.Dropper.Agent-5354692-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-5354692-0