Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 2c9ad963b0301cfc…

MALICIOUS

Office (OLE) / .DOC

23.0 KB Created: 1997-06-02 14:34:00 Authoring application: Microsoft Word 6.0
MD5: 111da7bb24fadc951786cf948a7c3ab6 SHA-1: 75b8cb51f568af0cb28e6102cddd2eb98ae1ec02 SHA-256: 2c9ad963b0301cfc40d2a47b752e5d69d8103e770c507157dc7d77f9e59910d2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link

The file is detected as Win.Trojan.MDMA-4 by ClamAV. The document body contains what appears to be technical specifications for manufactured parts, a common lure for malicious documents. No scripts were extracted from this sample, and the document body does not contain explicit instructions or links, making the exact attack vector less clear but the malicious intent evident from the heuristic detection.

Heuristics 1

  • ClamAV: Win.Trojan.MDMA-4 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.MDMA-4