Malicious Office (OLE) / .DOC — malware analysis report

Static analysis result for SHA-256 e7ddf9dcfe1179d6…

MALICIOUS

Office (OLE) / .DOC

11.5 KB Created: 1986-05-09 15:40:00 Authoring application: Microsoft Word 6.0
MD5: e16d0fab5d9c28165fdd617f5242d4be SHA-1: 0d34a9bbd49fabac092517b4b2291ab5d48cccc2 SHA-256: e7ddf9dcfe1179d6a079796db62767704de96aba30cd43de86394cc664ce8391
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.005 Visual Basic

The file is detected as Win.Trojan.Macro-11 by ClamAV, indicating a macro-based threat. The document body contains references to file paths and macro names like AUTOOPEN, suggesting the presence and execution of malicious VBA code. The specific macro functionality is not detailed, but the detection strongly implies it's designed to download and execute a secondary payload.

Heuristics 1

  • ClamAV: Win.Trojan.Macro-11 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Macro-11