Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 5e282a1238e82bc0…

MALICIOUS

Office (OLE) / .DOC

12.0 KB Created: 1997-08-08 19:14:00 Authoring application: Microsoft Word 6.0
MD5: 518cf5274caf75787bb6e7f8cf785d70 SHA-1: 97fd527cd7c439bfcdf50934679d81ff0082c6c4 SHA-256: 5e282a1238e82bc0328a74b4d67ce413b9d1622708e36d317a345044578a6562
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic T1566.001 Spearphishing Attachment

The file is a Microsoft Word document with a critical ClamAV heuristic firing for Win.Trojan.Macro-11, indicating the presence of malicious macro code. The document body contains unusual strings and references to AUTOOPEN, a common macro entry point. The macro is likely designed to download and execute a secondary payload, a common tactic for malware distribution.

Heuristics 1

  • ClamAV: Win.Trojan.Macro-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Macro-11