Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 4421f4867aada81b…

MALICIOUS

Office (OOXML) / .DOC

400.1 KB Created: 2025-11-11 01:26:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: ebade18938d9e032e8faa145fa3f6e0f SHA-1: b1903e84edc906d9b81d34de0a521317985a65ea SHA-256: 4421f4867aada81b3dcd67679b419a31c530e60dceb87fd274423d9147ade0be
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The OOXML document contains heuristics indicating remote template injection and external relationships, pointing to the loading of external resources. The embedded URL heuristic further supports this, suggesting the document is designed to fetch and execute content from a remote source, likely for a secondary payload delivery.

Heuristics 3

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://kutt.rhaimes.com/XT8UYv) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://kutt.rhaimes.com/XT8UYv
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.openxmlformats.org/markup-compatibili

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
emf_00.emf
24b6709b911affb19cc316e160db9f6ff879523bcce673f5961d1f76decf8de8
ooxml-emf OOXML EMF part: word/media/image1.emf 79704 bytes