Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 6265612c3219e022…

MALICIOUS

Office (OLE) / .EXE

9.5 KB Created: 1998-12-26 18:09:00 Authoring application: Microsoft Word for Windows 95
MD5: 41d02d54bea55d53d956af305828d73d SHA-1: ceaedc1243fe792333eb026e34481732c07fed2f SHA-256: 6265612c3219e022454df83bed2d4848058973f7aad29a700acea0e852229af7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The file is identified as a malicious document by ClamAV with the signature Doc.Trojan.MinSize-1, indicating it's a minimal-sized Trojan. The document body contains unusual strings and references to 'AutoOpen' and 'MinSize', suggesting an attempt to trigger an exploit upon opening. The authoring application and creation date point to an older version of Microsoft Word, likely targeted by this exploit.

Heuristics 1

  • ClamAV: Doc.Trojan.MinSize-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.MinSize-1