Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 4b2b6e8fc59aefc1…

MALICIOUS

Office (OLE)

402.5 KB Created: 2007-06-21 00:34:40 Authoring application: Microsoft Office PowerPoint
MD5: b52ad7d32e44ed6ed800628be27a4b3f SHA-1: 2e9f33f007876c039c05b0c43259d0f599c293f3 SHA-256: 4b2b6e8fc59aefc13ffaecf558302705a506c26fa80d28ddaf6d5648632ef230
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is flagged by ClamAV as Win.Spyware.Winspy-9772503-0, strongly suggesting spyware functionality. No specific IOCs or scripts were extracted for further analysis, limiting the ability to detail the attack vector or specific behaviors. The document body is generic and does not provide further clues.

Heuristics 1

  • ClamAV: Win.Spyware.Winspy-9772503-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Spyware.Winspy-9772503-0