Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 32411fcf6fde1479…

MALICIOUS

Office (OLE) / .EXE

9.5 KB Created: 1998-12-26 18:09:00 Authoring application: Microsoft Word for Windows 95
MD5: 7e98a2d7324674e9c6323093b23c6079 SHA-1: 05263e195f1fe51ad507cfda59fc95a31ce11de4 SHA-256: 32411fcf6fde1479ce53065c897ad49f486456023248103e547dc1ef70b54fe7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as a malicious executable by ClamAV with the signature Doc.Trojan.MinSize-1. Despite its .EXE extension, it contains metadata suggesting it originated from a Word 95 document template. The document body contains repetitive, seemingly template-related text, but no clear malicious instructions are present. The primary indicator of maliciousness is the ClamAV detection.

Heuristics 1

  • ClamAV: Doc.Trojan.MinSize-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.MinSize-1