Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 744c4f7d0b359dc6…

MALICIOUS

Office (OLE) / .EXE

15.0 KB Created: 1997-07-06 16:37:00 Authoring application: Microsoft Word for Windows 95
MD5: 9d681a58db7a4e78420dc714246d0d43 SHA-1: 24a276b5bbf78ceffc65edbfe2a599c15512d324 SHA-256: 744c4f7d0b359dc608f7568be4d7d24345c670cf0c651b3ba805fd348169ecac
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell

The file is detected as Win.Trojan.Concept-31 by ClamAV. Static analysis reveals embedded strings that appear to be commands for creating batch files, specifically 'c:\autoexec.bat' and 'c:\ac.bat'. These batch files likely contain instructions to download and execute a secondary payload, a common tactic for trojans.

Heuristics 1

  • ClamAV: Win.Trojan.Concept-31 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Concept-31