Malicious Office (OLE) / .DOCX — malware analysis report

Static analysis result for SHA-256 29e71a37b4ef4ed0…

MALICIOUS

Office (OLE) / .DOCX

15.0 KB Created: 1998-07-08 12:00:00 Authoring application: Microsoft Word 6.0
MD5: 3b640bdff4f7d9bb8dda993763c4e523 SHA-1: 3f2bbad0d5bec22546241a71e26f0fd89cc8f6d4 SHA-256: 29e71a37b4ef4ed05edbb59aa2a24f1e9eb0ae05df9f75f42ed4725e3e414fd5
60 Risk Score

Malware Insights

The file is detected as Win.Trojan.Alien-4 by ClamAV, indicating malicious intent. The presence of VBA macros, specifically AutoOpen, AutoClose, and FileSaveAs, suggests that the document is designed to execute malicious code upon opening or saving. The document body contains references to macro names and paths that are consistent with malware, but no specific IOCs could be extracted.

Heuristics 1

  • ClamAV: Win.Trojan.Alien-4 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Alien-4