Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 3f437cf03c8e5cb4…

MALICIOUS

Office (OOXML) / .DOC

10.1 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2022-06-17
MD5: 32edd7812feb0dcf761ec6fe5c13b058 SHA-1: f3d51c94824ba65283f70909076a0a0b01f37bdf SHA-256: 3f437cf03c8e5cb4f2c3c8531b68bc41bfb2c704c76d23578e369c56f3818a83
122 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The sample exhibits critical heuristic firings for ClamAV detection as Doc.Downloader.Redline, and also triggers high severity heuristics for remote template injection and external relationships. The presence of an unknown reputation URL, https://www.bot.ax/lbSWx, strongly suggests this document is designed to fetch and execute a secondary payload. The document body is minimal and does not provide further context.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://www.bot.ax/lbSWx) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://www.bot.ax/lbSWx
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.bot.ax/lbSWx
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml