Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 8bbf9ddf2ba65ec2…

MALICIOUS

Office (OLE) / .EXE

14.0 KB Created: 1997-01-26 08:59:00 Authoring application: Microsoft Word for Windows 95
MD5: f1dae1abef9a066d5eb8647465d6575e SHA-1: 0c0673f2d8e34280e641c479c9845594b110e3d3 SHA-256: 8bbf9ddf2ba65ec2a8cf2a32ac954796a38514bccdd13abb69940a8dce53e94f
60 Risk Score

Malware Insights

The file is detected as malicious by ClamAV with the signature 'Doc.Trojan.Wazzu-6'. The document body contains strings related to macros and document templates, suggesting a macro-based attack. The presence of 'autoOpen' and 'AUTOOPEN' further indicates that a macro is likely intended to execute automatically upon opening the document, aiming to deceive the user with a Microsoft Fax lure.

Heuristics 1

  • ClamAV: Doc.Trojan.Wazzu-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Trojan.Wazzu-6