Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 d45800c1e4f6e4a2…

MALICIOUS

Office (OLE)

13.5 KB Created: 1999-05-07 08:01:00 Authoring application: Microsoft Word for Windows 95
MD5: 5213ec0d1570ff2af76a7fc1ba42e430 SHA-1: 539e762c26bfbd2d70ed1b52865d1e8748772e82 SHA-256: d45800c1e4f6e4a2542339c6d07f314056a034ebff3ab23ed865a2ea4c399a0e
60 Risk Score

Malware Insights

The file is detected as Win.Trojan.Cap-1 by ClamAV. The document contains VBA macro names such as AutoExec, AutoOpen, and ToolsMacro, indicating a macro-based execution attempt. The presence of these macro names strongly suggests the document is designed to run malicious code when opened, likely to download and execute a secondary payload.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1