Malicious Office (OLE) / .EXE — malware analysis report

Static analysis result for SHA-256 d9b6c3a9c4a5fb15…

MALICIOUS

Office (OLE) / .EXE

14.0 KB Created: 1997-04-19 15:51:00 Authoring application: Microsoft Word for Windows 95
MD5: c7ee0722d598af96edd2b36cd751fe1c SHA-1: cc887f263cb25440526daf8c1f3da8c26ccfc974 SHA-256: d9b6c3a9c4a5fb15ada35c651f842a9fe920784782616ba830b42f458a12f129
60 Risk Score

Malware Insights

The file is an OLE executable with an AutoOpen macro, which is a common delivery mechanism for malware. ClamAV detected it as 'Win.Trojan.Nop-7'. The document body contains references to AutoOpen and file saving functions, suggesting macro execution is intended. No specific IOCs were extracted beyond the detection signature.

Heuristics 1

  • ClamAV: Win.Trojan.Nop-7 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Nop-7