Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 0dc2e40be32a9235…

MALICIOUS

Office (OOXML) / .DOC

9.1 KB Created: 2023-03-27 22:13:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-06-02
MD5: 1c496eb476e23806de3a11e8992200de SHA-1: 45663742b46dc5e6b0d1c547a0e77443083d0136 SHA-256: 0dc2e40be32a92354d1e3010fa16422ae2f9286cd44ecaa790b5b53037099747
142 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link

The file is identified as malicious by ClamAV and exhibits critical heuristic firings for remote template injection and external relationships. These indicators point to the document attempting to download a secondary payload from the URL http://194.180.48.59/obizx.doc. The document body contains what appears to be a parts list, likely a lure to disguise the malicious intent.

Heuristics 4

  • ClamAV: Doc.Downloader.Loda-7570590-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Loda-7570590-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (http://194.180.48.59/obizx.doc) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship high OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: http://194.180.48.59/obizx.doc
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://194.180.48.59/obizx.doc
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml