Formbook — Office (OOXML) / .DOCM malware analysis

Static analysis result for SHA-256 542793530faea71c…

MALICIOUS

Office (OOXML) / .DOCM

57.7 KB Created: 2022-07-03 16:34:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2022-07-13
MD5: 7292cb69b061e232f20811846c74cfc6 SHA-1: d3050dab760d4ac4440ca86e69d4b62187d0dd90 SHA-256: 542793530faea71c653341657df880c9c796f25ca3d0641bf5e08356739ad82f
62 Risk Score

Malware Insights

Formbook · confidence 95%

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The file is detected as a downloader for the Formbook malware family. While no specific document body text or scripts were provided for analysis, the ClamAV detection strongly indicates the file's purpose is to download and execute a second-stage payload. The embedded URLs, though benign in this case, are typical of downloader documents.

Heuristics 2

  • ClamAV: Doc.Downloader.Formbook-bc97c1e0c33c3c93-9951465-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Formbook-bc97c1e0c33c3c93-9951465-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml