Win.Worm.SomeFool-8 — Office (OLE) / .INF malware analysis

Static analysis result for SHA-256 4b637649842ac77e…

MALICIOUS

Office (OLE) / .INF

47.5 KB Created: 2004-05-04 16:29:00 Authoring application: Microsoft Word 8.0
MD5: 4460d4ea36a67ffa208300795ecabfbd SHA-1: 1703dce23c8d4b9d0312e0e5c25432f5a4b363e9 SHA-256: 4b637649842ac77e2b23b5e6febf94c0a61cc2a1574163e576237cc9c6d05f4d
60 Risk Score

Malware Insights

Win.Worm.SomeFool-8 · confidence 85%

MITRE ATT&CK
T1059.001 PowerShell

The primary indicator is the ClamAV detection of 'Win.Worm.SomeFool-8', strongly suggesting a worm. No document body or script content was available for further analysis, limiting the ability to detail the specific delivery or execution mechanisms. The file type is an INF file, which can be used to distribute and install software, including malware.

Heuristics 1

  • ClamAV: Win.Worm.SomeFool-8 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Worm.SomeFool-8