Office (OOXML) / .DOC static analysis report

Static analysis result for SHA-256 14fe05fa955c757f…

SUSPICIOUS

Office (OOXML) / .DOC

41.2 KB Created: 2021-06-29 14:31:00 UTC Authoring application: Microsoft Office Word 16.0000 First seen: 2021-07-02
MD5: f1cfc0bd5e06180e32cd6ec7eac66aee SHA-1: 87aac6459d890b1715396b8c223de4d3ae81b48f SHA-256: 14fe05fa955c757ff2726ec79af3d93fe217d1daeff0724c526a4432e9772b1a
50 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample contains an external relationship pointing to a local template file, suggesting an attempt to trick the user into opening a malicious document. It also includes an external hyperlink to an email address, potentially for social engineering. No scripts were extracted, and the document body was truncated, limiting further analysis.

Heuristics 3

  • External relationship high OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: file:///C:\Users\ekranz\AppData\Roaming\Microsoft\Templates\Quarterly earnings press release.dot
  • External hyperlinks (1) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 1 external hyperlink — clickable URLs are stored as external relationships. First target: mailto:ekranz@dearborncountychamber.org
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas Document hyperlink
    • http://schemas.microsoft.com/office/drawing/2014/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2015/10/21/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/9/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/10/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/11/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/12/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/13/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/14/chartexDocument hyperlink
    • http://schemas.openxmlformats.org/markup-compatibility/2006Document hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/inkDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2017/model3dDocument hyperlink
    • http://schemas.openxmlformats.org/officeDocument/2006/relationshipsDocument hyperlink
    • http://schemas.openxmlformats.org/officeDocument/2006/mathDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingDocument hyperlink
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingDocument hyperlink
    • http://schemas.openxmlformats.org/wordprocessingml/2006/mainDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2012/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2018/wordml/cexDocument hyperlink
    • http://schemas.microsoft.com/office/word/2016/wordml/cidDocument hyperlink
    • http://schemas.microsoft.com/office/word/2018/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2020/wordml/sdtdatahashDocument hyperlink
    • http://schemas.microsoft.com/office/word/2015/wordml/symexDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroupDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInkDocument hyperlink
    • http://schemas.microsoft.com/office/word/2006/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShapeDocument hyperlink