Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 58ada14e395651a3…

MALICIOUS

Office (OLE) / .EXE

19.0 KB Created: 1993-09-28 16:08:00 Authoring application: Microsoft Word for Windows 95
MD5: 864ce53a2c5711327cc7fe68c8104ab3 SHA-1: fd59398ad84ffd8ab2620e01713e1feab10bddf6 SHA-256: 58ada14e395651a3880e4db128d31c18c325562467e0e71abd312bddec6edbc8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is identified as a malicious executable by ClamAV with the signature Win.Trojan.Wazzu-37. Although the document body contains seemingly innocuous text about concerts and gems, the file type and heuristic detection strongly indicate a malicious payload. No scripts were extracted, and the document content does not provide further clues about the specific attack vector.

Heuristics 1

  • ClamAV: Win.Trojan.Wazzu-37 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Wazzu-37