Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 9fc495131d241fee…

MALICIOUS

Office (OLE) / .EXE

22.0 KB Authoring application: Microsoft Excel
MD5: 16d9b2dbb6ca2720c24c33d9224180f8 SHA-1: f7b1a22bde9eddd738d0df62a48e4a6c354d4035 SHA-256: 9fc495131d241fee4e0cb690e667f0ba6b1b705935f3b3bd84337a1eda6b5f79
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as a malicious executable by ClamAV with the signature Win.Trojan.Laroux-12. Although it is presented as an Office file, the executable nature and the generic detection suggest it's a trojan dropper. The document body contains financial terms, indicating a potential lure for financial scams or phishing.

Heuristics 1

  • ClamAV: Win.Trojan.Laroux-12 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Laroux-12