Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 c9110125f4c967f5…

MALICIOUS

Office (OLE) / .DOC

10.5 KB Created: 1996-12-11 20:14:00 Authoring application: Microsoft Word 6.0
MD5: ac84f537f34340229b6f4bb097250f6e SHA-1: 61805b043f791989b620fb33ada52f11d7c7474f SHA-256: c9110125f4c967f51e62d78dd9af3e12cf491bc5726b6f1786872b3e51ed66c0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is a legacy DOC format, and the CLAMAV_DETECTION heuristic indicates it is a known macro-based threat. The presence of 'AUTOOPEN' suggests a macro is intended to execute automatically upon opening. While no specific VBA code is provided, the file's age and heuristic firing strongly suggest a macro-based attack, likely attempting to exploit older vulnerabilities or deliver a payload.

Heuristics 1

  • ClamAV: Win.Trojan.Macro-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Macro-11