MALICIOUS
80
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is an encrypted Office document, which is a common tactic to evade static analysis and hide malicious content. ClamAV detection as 'Doc.Dropper.Agent-1847916' strongly suggests its purpose is to download and execute a second-stage payload. The encryption prevents analysis of the document body or any embedded scripts.
Heuristics 2
-
ClamAV: Doc.Dropper.Agent-1847916 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Dropper.Agent-1847916
-
Office document is password-encrypted medium OFFICE_ENCRYPTED_PACKAGEOLE container holds MS-OFFCRYPTO encrypted package (Standard Encryption (Office 2007, AES)).
Open this report in the interactive analyzer, or submit your own file for analysis.