Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 50e86c5555e11ef2…

MALICIOUS

Office (OOXML) / .DOC

11.5 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 15.0000
MD5: dc8d1763959f01449551d776e4ca489d SHA-1: 741d0b9d5fc2503558892489acb640265f198d0d SHA-256: 50e86c5555e11ef2c8857ccc4a49e90fa42163b5a6f8f42ec43b54005a63c38d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is identified as malicious by ClamAV and exhibits characteristics of remote template injection and external relationship usage. The presence of these heuristics suggests the document is designed to pull content from an external source, likely to download and execute a secondary payload. The URL associated with these heuristics, while marked as benign, is still considered a potential indicator of compromise in this context.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://is.gd/DjSoAL) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://is.gd/DjSoAL
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://is.gd/DjSoAL
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape