user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat TrojanDownloader:O97M/Encdoc.PKR
TrojanDownloader:O97M/Encdoc.PKR - Windows Defender threat signature analysis

TrojanDownloader:O97M/Encdoc.PKR - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: TrojanDownloader:O97M/Encdoc.PKR
Classification:
Type:TrojanDownloader
Platform:O97M
Family:Encdoc
Detection Type:Concrete
Known malware family with identified signatures
Variant:PKR
Specific signature variant within the malware family
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: Trojan Downloader - Downloads additional malware for O97M platform, family Encdoc

Summary:

TrojanDownloader:O97M/Encdoc.PKR is a malicious macro embedded within a Microsoft Office document. When the user enables macros, it downloads and executes a secondary, more dangerous payload from a remote server. This action can lead to a more severe infection, such as ransomware or an information stealer.

Severity:
High
VDM Static Detection:
No specific strings found for this threat
Remediation Steps:
Ensure the detected file is deleted or quarantined. Run a full system scan with updated antivirus signatures to detect any secondary payloads. Harden Microsoft Office macro security settings via Group Policy to prevent execution from untrusted sources.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 09/11/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$