Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 701d54de5b893983…

MALICIOUS

Office (OLE)

16.0 KB
MD5: 0d61c3950cd622d27d06384316a6a482 SHA-1: 1fb8e695b28ec415e734a37eca2d0e110c35e4d7 SHA-256: 701d54de5b89398324d0b75491d26df59bb066010438014ecfe0521e7f83f930
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as a malicious macro virus by ClamAV. The document body explicitly mentions 'RSN MACRO VIRUS Goat file' and lists several VBA macro names such as AutoOpen and AutoExec, indicating that malicious code is intended to run automatically when the document is opened. This suggests an attack pattern involving malicious macros delivered as an attachment.

Heuristics 1

  • ClamAV: Win.Trojan.Color-3 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Color-3