Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 51727a94ebd0dc8d…

MALICIOUS

Office (OLE)

9.0 KB Created: 2018-11-15 21:00:12 First seen: 2018-11-20
MD5: eec18c4d4f74a47be6df6d23a4b82d4b SHA-1: 49c00b30cc9ab616ed180ea21f2e66c4dabf84dc SHA-256: 51727a94ebd0dc8d24fd8ab602220aa6a6fe07cb1ed02ac4b2cd98cd5ba59d4f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File

The file is detected by ClamAV as a dropper, indicating its primary function is to deliver other malware. The document body's warning about viruses is a common social engineering tactic to bypass user caution. While no specific family is identified, its dropper nature suggests it's part of a multi-stage attack.

Heuristics 1

  • ClamAV: Doc.Dropper.Agent-6853627-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6853627-0