Malicious Office (OLE) / .DOCX — malware analysis report

Static analysis result for SHA-256 bfc404b6a4f99084…

MALICIOUS

Office (OLE) / .DOCX

11.0 KB Created: 2001-09-13 09:27:00 Authoring application: Microsoft Word for Windows 95
MD5: 1470869cfe65d315375f4a903090c896 SHA-1: 03d9875d9e50cbf0c6105a83643d53006a5e9677 SHA-256: bfc404b6a4f99084a83993f3412a52aa71437140d4580801d6f3bae86e86a51d
60 Risk Score

Malware Insights

The file is detected as Win.Trojan.Apparition-11 by ClamAV. The document body contains VBA macro names such as AutoOpen, WWUpdat, and DaniloffMuDaK, which are commonly associated with macro-based malware. These macros likely execute malicious code upon opening the document, potentially downloading and running additional payloads.

Heuristics 1

  • ClamAV: Win.Trojan.Apparition-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Apparition-11