Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 7bac58e64e8334e8…

MALICIOUS

Office (OLE) / .EXE

13.0 KB Created: 1601-01-01 00:00:00 Authoring application: Microsoft Word 6.0
MD5: 620635b9a91562c9797f4ceb3159c54d SHA-1: 4e3562dc235343bf53367a1f2ed6f7c69e23ba16 SHA-256: 7bac58e64e8334e846d5588478873271ae534b601ccff1e92f3d17fd943b573d
60 Risk Score

Malware Insights

The file is detected as a Trojan by ClamAV. The document body contains VBA macro-related keywords such as 'autoOpen', 'fileMacro', and 'globMacro', indicating the presence and likely execution of malicious macros. The macro's purpose appears to be downloading and executing a secondary payload, though the specific mechanism is not detailed in the extracted evidence.

Heuristics 1

  • ClamAV: Doc.Trojan.Wazzu-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Wazzu-6