MALICIOUS
242
Risk Score
Heuristics 4
-
ClamAV: Win.Trojan.Agent-1222418 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Trojan.Agent-1222418
-
Embedded PE executable critical OLE_EMBEDDED_EXEMZ/PE header found inside document — possible embedded executable
-
Ole10Native package drops an auto-executable payload critical OFFICE_PACKAGE_RISKY_FILEOLE Package displayName or fullPath ends in a directly auto-executable extension (a runnable binary or a script the default shell host runs on double-click). Embedding such a payload inside an Office document has no benign authoring use — it is a malware-delivery dropper.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.openxmlformats.org/drawingml/2006/main In document text (OLE body)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_office_00003884.exe |
embedded-pe | Office MZ+PE at offset 0x3884 | 259452 bytes |
SHA-256: 68a941fa7551e50ce5873109919506e1b89966530df489daa8ce9ac987562a59 |
|||
|
Detection
ClamAV:
Win.Trojan.Agent-1222418
Obfuscation or payload:
unlikely
|
|||
ole10native_00.bin |
ole-package | OLE Ole10Native stream: ObjectPool/_1475761331/Ole10Native | 250251 bytes |
SHA-256: 4ccf4e83f7a91640a1b5818d75088fc1df0839373d9ef2217806f9d11d4ee258 |
|||
|
Detection
ClamAV:
Win.Trojan.Agent-1222418
Obfuscation or payload:
unlikely
|
|||
ole10native_00_done.exe |
ole-package-payload | OLE Ole10Native payload: ObjectPool/_1475761331/Ole10Native; display_name=done.exe; full_path=C:\Users\TMONEY\AppData\Local\Temp\done.exe; temp_path=; def_file= | 249885 bytes |
SHA-256: 9d416f9e4a04e41e7c17d6ff6ea682cb3f0a81c4c0695d57f4ff4cdf13d3a93a |
|||
|
Detection
ClamAV:
Win.Trojan.Agent-1222418
Obfuscation or payload:
unlikely
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.