Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 a8f7dcccd71414d0…

MALICIOUS

Office (OLE)

23.0 KB Created: 1997-09-17 15:19:00 Authoring application: Microsoft Word 6.0
MD5: 48e20ca33df1ea2e57082ecce9851b7d SHA-1: 14e5a3e9d31317ee06cce1ee864cf22fc0cf491c SHA-256: a8f7dcccd71414d045a764f381f16450e385ec25aae16a5136ffc997e0b13f40
60 Risk Score

Malware Insights

The file is detected as Win.Trojan.Cap-1 by ClamAV. The document body presents a form for evaluating a mobility grant, likely a social engineering lure to encourage macro execution. The presence of VBA macro names such as AutoExec, AutoOpen, and ToolsMacro strongly suggests that malicious VBA code is embedded within the document, intended to be executed upon opening or interaction, which is consistent with a trojan delivery mechanism.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1