Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 3273e6077c8f2cb8…

MALICIOUS

Office (OLE) / .EXE

14.0 KB Created: 1997-02-27 22:48:00 Authoring application: Microsoft Word for Windows 95
MD5: 53b18d1413491e9d9c50a30de1ad8a9e SHA-1: a11b7900149b68a222aaf2a2950b29b736773482 SHA-256: 3273e6077c8f2cb85b248de19e360e1c3184c9cd80b83b186327728dbf3ff0d3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as a malicious executable by ClamAV with the signature 'Doc.Trojan.Wazzu-6'. Although it is an OLE file, the 'file_type' indicates it's an executable. The document body contains strings related to Word macros and templates, suggesting a potential macro-based execution or a packed executable masquerading as a document. The authoring application and creation date suggest an older file, possibly exploiting legacy vulnerabilities.

Heuristics 1

  • ClamAV: Doc.Trojan.Wazzu-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Wazzu-6