Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 4fd7960aac1bfe30…

MALICIOUS

Office (OLE) / .DOC

96.5 KB Created: 1998-07-03 00:46:00 Authoring application: Microsoft Word for Windows 95
MD5: c08b175b6ddaa394a50ff115c84b716f SHA-1: 64198acae457cb60c3dfba64b71a5b25e3a8b128 SHA-256: 4fd7960aac1bfe30e290aba5d107ee4527f86d9082d5994733899e6aee96df73
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1566.002 Spearphishing Link

The file is detected as Win.Trojan.Dementia-4 by ClamAV, indicating malicious intent. The document body presents a fabricated travel itinerary, a common social engineering lure to deceive recipients. While no scripts were extracted, the document structure and the ClamAV detection strongly suggest a phishing or malware delivery attempt.

Heuristics 1

  • ClamAV: Win.Trojan.Dementia-4 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Dementia-4