Malicious Office (OLE) / .HTM — malware analysis report

Static analysis result for SHA-256 f9717e4064f138ad…

MALICIOUS

Office (OLE) / .HTM

15.5 KB Created: 1997-06-23 03:56:00 Authoring application: Microsoft Word for Windows 95
MD5: 0106c12b659163145ba5b072acab07f0 SHA-1: c3bb99f0c60cae102bb2ba7f098118957fbb69dc SHA-256: f9717e4064f138ad79cce92cf2cdab80ce75f72243fcfc7758a45d079feef325
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as malicious by ClamAV with the signature Win.Trojan.GreenBay-1. The document body, disguised as an educational project description about grocery prices, is likely a lure to encourage the user to interact with the file, potentially leading to the execution of a malicious payload. No scripts were extracted from this sample.

Heuristics 1

  • ClamAV: Win.Trojan.GreenBay-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.GreenBay-1