Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 bb49a787825e8ea3…

MALICIOUS

Office (OLE) / .DOC

14.0 KB Created: 1997-02-18 14:51:00 Authoring application: Microsoft Word 6.0
MD5: c545f8b929e11174735e16d2f9570547 SHA-1: a092c0ed004083401b89203e187a9bd915544a2b SHA-256: bb49a787825e8ea36edc0942e41e65b0fa2db9eb8c314182736f4704588db9cb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic for Applications

The file is detected as Win.Trojan.Macro-11 by ClamAV, indicating a macro-based threat. The document body contains references to file paths and printer names, likely intended to obfuscate or distract from the malicious macro's execution. No scripts were extracted, limiting further analysis of the macro's specific behavior.

Heuristics 1

  • ClamAV: Win.Trojan.Macro-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Macro-11