Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 9f01e9b4c50684ea…

MALICIOUS

Office (OLE) / .DOC

20.0 KB Created: 1997-12-04 02:27:00 Authoring application: Microsoft Word for Windows 95
MD5: 64d45862eefe3399d721a274be73711e SHA-1: cef701e59eb338c8ff01e5dafa1b0fdd3f828acd SHA-256: 9f01e9b4c50684ea3a043d0260adcf6ac7f630b29554cb569b29084faf69cf60
60 Risk Score

Malware Insights

The file is detected as Win.Trojan.Cap-1 by ClamAV. While no specific malicious scripts were extracted, the presence of numerous VBA macro names like AutoOpen, FileOpen, and ToolsMacro suggests that the document is designed to execute malicious code upon opening. The document body is a curriculum vitae, a common lure for social engineering attacks.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1