Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 8b7f77d87b79a816…

MALICIOUS

Office (OLE)

26.5 KB Created: 1998-05-04 16:08:00 Authoring application: Microsoft Word for Windows 95
MD5: d7ed626e886cd8529033a477ba68d181 SHA-1: 0da5ae3a4e0688b7155b086c309b7e0cc9f03c17 SHA-256: 8b7f77d87b79a816515cf951807df4fd0c185f42817a6e849c1c96579a091ffb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The file is an OLE document with a detected ClamAV signature of Win.Trojan.Cap-1. The document body appears to be a project diary, likely a lure to disguise malicious intent. No scripts were extracted, and the document body does not contain any obvious malicious instructions. The primary indicator of compromise is the ClamAV detection signature.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1