Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 76a95fd58ca606e8…

MALICIOUS

Office (OLE)

21.5 KB Created: 1997-01-25 11:37:00 Authoring application: Microsoft Word 6.0
MD5: 0821830306a646f93ce79a4c7c792d57 SHA-1: 5f9378baa1ddf5559f625c6ee7bef085be5dbfe9 SHA-256: 76a95fd58ca606e85e6f28f572aa0f2425d19860b2aaa48a3a1557bd98acd56c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as malicious by ClamAV with the signature Win.Trojan.Tm-1. The document's metadata indicates it is a Microsoft Word 6.0 file, suggesting a potential exploit targeting older versions of Word. The presence of AUTOOPEN and references to DLLs and DOC files within the document body further support the likelihood of malicious macro execution.

Heuristics 1

  • ClamAV: Win.Trojan.Tm-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Tm-1