Win.Trojan.Cap-1 — Office (OLE) / .DOC malware analysis

Static analysis result for SHA-256 5270d59ee4b30a5a…

MALICIOUS

Office (OLE) / .DOC

22.0 KB Created: 1997-07-06 18:06:00 Authoring application: Microsoft Word for Windows 95
MD5: ca9ea871a238c908d96c0ff5986d7ec6 SHA-1: 0c926303da64e05a2b62104bc4bd1e93bb8d7c54 SHA-256: 5270d59ee4b30a5ae6a52f7e37e10a4cf1e1e385d167545664c5aae3a2175fcf
60 Risk Score

Malware Insights

Win.Trojan.Cap-1 · confidence 85%

MITRE ATT&CK
T1204.002 Malicious File

The file is detected as Win.Trojan.Cap-1 by ClamAV. The document contains VBA macro names such as AutoExec, AutoOpen, and FileOpen, indicating it likely attempts to execute malicious code upon opening. The presence of embedded file paths suggests potential payload staging or origin.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1