Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 1dd1c52e5eb1b1e5…

MALICIOUS

Office (OOXML) / .DOC

222.3 KB Created: 2022-08-08 11:17:00 UTC Authoring application: Microsoft Office Word 16.0000 First seen: 2022-08-12
MD5: 47d9189cc83bbed4a6e2b2a2e9cb8db6 SHA-1: 6754f664e53de82474dcfe3a0deeb022c8f802c1 SHA-256: 1dd1c52e5eb1b1e5c4abc7c327b63687528118e612e9a42f01b97955676f4ff0
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: User Execution T1059 Command and Scripting Interpreter

The sample leverages an OOXML OLE2Link object, related to CVE-2017-0199, to load external content from the URL https://support-office-us.herokuapp.com/Documents. This indicates a likely attempt to download and execute a second-stage payload, characteristic of a downloader or initial access exploit.

Heuristics 3

  • OOXML OLE2Link remote loader — CVE-2017-0199 related high CVE related CVE_2017_0199_RELATED
    Document contains an o:OLEObject Type=Link whose external oleObject relationship points to a remote URL. This is the OOXML OLE2Link activation shape associated with CVE-2017-0199 delivery, but the local file does not expose URL Moniker bytes or a weaponized extension/content type, so the exact CVE cannot be proven statically.
  • External OLE object relationship high OOXML_EXTERNAL_OLE_OBJECT
    Document contains an oleObject relationship whose target is an external HTTP(S) URL. Office resolves this through OLE/object update paths rather than as a normal user-clicked hyperlink.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://support-office-us.herokuapp.com/Documents
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/photoshop/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
emf_00.emf
f642664b165d18d450734d69e5ac545aa4c96ed7d89419bd2f2cd4af822a0316
ooxml-emf OOXML EMF part: word/media/image3.emf 5196 bytes