Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 51329de0ae092721…

MALICIOUS

Office (OLE)

17.0 KB First seen: 2012-06-14
MD5: 155b63cde5c29609dfe07613707230ce SHA-1: ecff6377af7e3e35a7c9c09ba14fda3405d892a8 SHA-256: 51329de0ae092721120514bbc8bb39494049f31f711684c70dab14ea71cfe58a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file was detected by ClamAV as Legacy.Trojan.Agent-495, indicating it is a known malicious legacy trojan. The document body contains garbled text, suggesting potential obfuscation or corruption, and no executable scripts were extracted. The primary finding is the ClamAV detection, pointing towards exploitation for client execution.

Heuristics 1

  • ClamAV: Legacy.Trojan.Agent-495 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Legacy.Trojan.Agent-495