Malicious Office (OLE) / .DOCX — malware analysis report

Static analysis result for SHA-256 c357e8c86867a0c0…

MALICIOUS

Office (OLE) / .DOCX

49.5 KB Created: 1998-03-18 18:55:00 Authoring application: Microsoft Word for Windows 95
MD5: 20752e622e6e873135c65d661c120899 SHA-1: 9b637e4462bf5bf9e101d14eb4a3e96494b22436 SHA-256: c357e8c86867a0c0fbf20dcbe5f76ad3256fa7371355d3c1c239b802df11fdf9
60 Risk Score

Malware Insights

The file is an older Word 95 document containing VBA macros. The CLAMAV_DETECTION heuristic identified it as Win.Trojan.Attach-1. The extracted document body text and office facts indicate the presence of VBA code designed to present a file conversion wizard to the user. This is a common lure for macro-based malware, likely intended to download and execute a second-stage payload.

Heuristics 1

  • ClamAV: Win.Trojan.Attach-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Attach-1