Remote image (web beacon / tracking pixel)

OOXML_IMAGE_BEACON

← All detection heuristics · Office

medium OOXML_IMAGE_BEACON

What it means

Document contains an external image relationship targeting an http(s):// URL.

Why it fires

An image relationship with an external http:// or https:// target is fetched by Office when external content is allowed. This can reveal the victim's IP address and timestamp to the attacker's server (tracking beacon). In some Windows Integrated Authentication configurations, the request may also expose NTLM authentication material, but plain HTTP image fetches are not a guaranteed NTLM-leak path. Caveat: documents exported from web-based editors or CMS platforms may include externally-hosted images; verify whether the target URL is a known-legitimate host before escalating.

Other Office heuristics

OLE_VBA_AFFINE_MSI_DOWNLOADER OLE_VBA_AUTOEXEC_FRAGMENTED_SHELL OLE_VBA_DESTRUCTIVE_WORKBOOK_SHUTDOWN OLE_VBA_BIDIRECTIONAL_MACROCOPY_REPLICATION OOXML_BRAND_LINK_MISMATCH_LURE CVE_2016_7262 POLYGLOT_OOXML_REL_COMMAND OLE_RAW_PCODE_CROSS_DOCUMENT_REPLICATION OLE_VBA_CROSS_WORKBOOK_REPLICATION OOXML_XLM_DANGEROUS_FN OFFICE_DEFAULT_PASSWORD_VBA_DROP_EXEC OFFICE_EMBEDDED_SWF EMBEDDED_OFFICE_CHILD_STATIC_TRIAGE OFFICE_EMBEDDED_MACRO_OBJECT OLE_EMBEDDED_EXE OLE_VBA_EMBEDDED_PE_DROPPER OLE_ENCRYPTED_AND_MALFORMED CVE_2017_11882_EQUATION_NATIVE_CMD_RELATED CVE_2017_11882 OLE_EQUATION_OLE10NATIVE_DOWNLOADER OLE_MTEF_NATIVE_CODE_STUB OLE_EQUATION_OLE10NATIVE_SHELLCODE OOXML_XLM_MACRO_IN_WORKSHEET OLE_XLS5_LAROUX_MACRO_VIRUS