Wazzu — Office (OLE) / .EXE malware analysis

Static analysis result for SHA-256 f9121cff26861af2…

MALICIOUS

Office (OLE) / .EXE

12.5 KB Created: 1996-08-25 01:18:00 Authoring application: Microsoft Word for Windows 95
MD5: 3149bfa69b1cb7c133955d339844d195 SHA-1: 4f74c40b4dd0a5d0af6ce8dff0b2f4082a2d5324 SHA-256: f9121cff26861af2218d760a2b4933fdbc95d9293a1f5f606fadd4baf9a0d24a
60 Risk Score

Malware Insights

Wazzu · confidence 95%

MITRE ATT&CK
T1204.002 Malicious File

The file is identified by ClamAV as Win.Trojan.Wazzu-46. The document body explicitly states it is a 'goat DOC file for the Wazzu Word-For-Windows Macro virus' and mentions 'Mark Brouwer' and 'C:\VIRUSRES\MACRO\wazzu.doc', further confirming the Wazzu family and its macro-based delivery. The primary attack vector is social engineering through a malicious document.

Heuristics 1

  • ClamAV: Win.Trojan.Wazzu-46 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Wazzu-46