Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 261843e6e614aae5…

MALICIOUS

Office (OLE) / .EXE

27.0 KB Created: 1997-08-17 13:29:00 Authoring application: Microsoft Word 6.0
MD5: c6ef5ee699ef8e24bd74b5bb9042d3a9 SHA-1: c9e55f723039bdb485c99302bc029bf76ffc3ee0 SHA-256: 261843e6e614aae52af615ae997fa048f0a35247ffdb9bf3059587e30a951f52
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is an OLE executable disguised as an academic document. Static analysis identified it as Win.Trojan.Cap-1. The document content appears to be a legitimate academic paper, which is a common lure for social engineering attacks. The executable nature of the file, combined with the malware detection, suggests it is designed to deliver a payload upon execution.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1