MALICIOUS
82
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The sample exhibits characteristics of a malicious OOXML document, specifically remote template injection and the presence of an embedded OLE object. The embedded OLE object and remote template injection are likely used to download and execute a secondary payload from the unknown URL. The document body was truncated and did not provide further context on the lure.
Heuristics 4
-
Remote template injection high OOXML_REMOTE_TEMPLATEDocument references a remote template URL (https://wrath.me/HXwkrG) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
-
External relationship medium OOXML_EXTERNAL_RELExternal target in word/_rels/settings.xml.rels: https://wrath.me/HXwkrG
-
Embedded OLE object medium OOXML_OLE_OBJECTDocument contains an embedded OLE object
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://wrath.me/HXwkrG
- http://schemas.openxmlformats.org/markup-compatibility/2006
- http://schemas.openxmlformats.org/officeDocument/2006/relationships
- http://schemas.openxmlformats.org/officeDocument/2006/math
- http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
- http://schemas.openxmlformats.org/wordprocessingml/2006/main
- http://schemas.microsoft.com/office/word/2006/wordml
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
ooxml_oleobject_00.bin9b7393478aedf4b44389d245d64927b097f76958b50e26bfb0e6fcb807de1568 |
ooxml-ole-object | OOXML embedded OLE part: word/embeddings/oleObject1.bin | 1777664 bytes |
ooxml_oleobject_01.bineb839f5d2cdeb19a8591e566fba30cf4e0787d591fba4521207909bbe7f7871b |
ooxml-ole-object | OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Worksheet3.xlsx | 31542 bytes |
ooxml_oleobject_02.bin17e8126278ced17e8806c35662d77133f43d7bc05e9e25581657d5ad7a011750 |
ooxml-ole-object | OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Worksheet1.xlsx | 224197 bytes |
ooxml_oleobject_03.bind88539c6475d7cbf991bd49acc4265ecb400f8fca3a38472c7ed93d9e124ab30 |
ooxml-ole-object | OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Worksheet2.xlsx | 23896 bytes |
ooxml_oleobject_04.bin337c3dd9b8f44fa49ef21fe572b41328a2ef455202b62e9635d413aaa475c287 |
ooxml-ole-object | OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Worksheet4.xlsx | 33182 bytes |
emf_00.emff5914f695c0f58cb99246e66470c16ff7f1be6c63010600bf0c4e4c7a130ba99 |
ooxml-emf | OOXML EMF part: word/media/image5.emf | 50496 bytes |
emf_01.emf0c5d26a995ca6be9a4fede95b958dcf3039e10c857ab260c54f466020664eb16 |
ooxml-emf | OOXML EMF part: word/media/image4.emf | 86860 bytes |
emf_02.emfcf9f717e428092bc8bd924b874c8e584aa0fb8743e3cab6324fb5a7ee330a356 |
ooxml-emf | OOXML EMF part: word/media/image1.emf | 187044 bytes |
emf_03.emff328fb5b6055b687344190bb13d8dd6cdf6ea76d4aaae6c5112dec1b32ace3c2 |
ooxml-emf | OOXML EMF part: word/media/image2.emf | 1504468 bytes |
emf_04.emfc9cd67f73e83803fb9be2b79c03cbcfb9515ae50203fe4368124d75c5aae3a28 |
ooxml-emf | OOXML EMF part: word/media/image3.emf | 97656 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.