Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 b24ecbc26a913c98…

MALICIOUS

Office (OLE) / .DOC

14.0 KB Created: 1997-09-16 14:14:00 Authoring application: Microsoft Word for Windows 95
MD5: 9b6f92788a60b62aaa65ba040ed46e32 SHA-1: 98058612276ae5d58dc961c36e5bd87413428ffd SHA-256: b24ecbc26a913c980d54976143076009936ceb06d142b792807162b9504804be
60 Risk Score

Malware Insights

The file is an OLE document with a detected ClamAV signature of Win.Trojan.W-283. While no specific malicious script content was extracted, the presence of numerous AutoOpen, AutoClose, and Appder macros within the document structure strongly suggests an attempt to execute malicious code upon opening or closing the document. The document body contains address information, likely a lure to encourage opening.

Heuristics 1

  • ClamAV: Win.Trojan.W-283 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.W-283