Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 429f014ba889ab27…

MALICIOUS

Office (OOXML) / .DOC

10.1 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: de9a113aeb2df3f2f95a360e558216a1 SHA-1: 485854d80aa4b73938b6ce516f2e117f55304074 SHA-256: 429f014ba889ab27006497329928e7e65f2eae28426bda6fcc28df60236b0a1a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is a malicious OOXML document detected as a downloader by ClamAV. It utilizes remote template injection, indicating an attempt to fetch and execute content from an external source. The embedded URL, though marked as benign, is likely used in the attack chain. No scripts were extracted, limiting the ability to detail the exact payload execution.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://is.gd/rAwPmo) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://is.gd/rAwPmo
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://is.gd/rAwPmo
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml