Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 b7b91e19e7c541e3…

MALICIOUS

Office (OLE) / .DOC

618.5 KB
MD5: 0b4bb52e5e865a40484f2caae9d21d61 SHA-1: 4a439bb27ce7b6ecef10dd7a656c68cef60d8e0b SHA-256: b7b91e19e7c541e3d5501278413f20d3119452a93d938566dbb23c34e14234dc
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is an encrypted Office document, which is a common delivery mechanism for malware. ClamAV detection as 'Doc.Dropper.Agent-7653996-0' strongly indicates its purpose is to drop and execute additional malicious content. Without extractable document body or scripts, the exact payload and delivery method remain unclear, hence the lower confidence.

Heuristics 1

  • ClamAV: Doc.Dropper.Agent-7653996-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-7653996-0