Malicious Office (OOXML) / .DOCX — malware analysis report

Static analysis result for SHA-256 14bd1ab23d135438…

MALICIOUS

Office (OOXML) / .DOCX

54.8 KB Created: 2011-12-14 08:29:00 UTC Authoring application: Microsoft Office Word 15.0000
MD5: 92b1c50c3ddf8289e85cbb7f8eead077 SHA-1: 2d22bf18ab1a8db0309c477472b481b0641b9dc7 SHA-256: 14bd1ab23d13543835821dd1fa5c17fc8c055341d09694971b5f2775c634f66e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is detected as a malicious dropper by ClamAV. The document body contains placeholders for an image and text, suggesting a lure to trick the user into interacting with the document. The presence of embedded URLs, though benign in this case, is common in malicious documents designed to download further payloads.

Heuristics 2

  • ClamAV: Doc.Dropper.Agent-6774287-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6774287-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape