Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 e27b52241c0386c6…

MALICIOUS

Office (OLE) / .DOC

15.0 KB Created: 1996-05-20 03:05:00 Authoring application: Microsoft Word for Windows 95
MD5: 910cceed647b7cd1e89d72c748800925 SHA-1: 1a2106895c27aff95daddb95e3f75500b3af2c4d SHA-256: e27b52241c0386c6f2d29320050c7d22e1bad4eea24fa8d9a5eb720abdcbf909
60 Risk Score

Malware Insights

The file is a Microsoft Word 95 document with a high likelihood of containing malicious VBA macros, as indicated by the ClamAV detection 'Win.Trojan.Cap-1'. The presence of auto-execution functions like 'AutoOpen' and 'AutoExec' within the document body strongly suggests an attempt to execute arbitrary code when the document is opened. No specific IOCs like URLs or hashes were extracted, and the family could not be determined.

Heuristics 1

  • ClamAV: Win.Trojan.Cap-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Cap-1