Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 55ffdf7a21436550…

MALICIOUS

Office (OOXML) / .DOC

73.6 KB Created: 2015-07-05 02:11:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: dc407f26a38d4a0739f3b56323e61225 SHA-1: 2772ad55bc3ec87ca6f66d58b14e9e7527d262e3 SHA-256: 55ffdf7a214365501a7fe750d4a3e3a79dc5a2b85279b3c38c5fa6a0ba4d6443
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document's body text clearly indicates an advance-fee scam, impersonating a solicitor to claim a large inheritance. The presence of an embedded OLE object suggests the potential for further malicious activity, such as dropping additional payloads or executing embedded scripts. No scripts were extracted from this sample, limiting the analysis of the exact execution chain.

Heuristics 3

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
ef8865c51136af8edd0b6c026c676120041966ddef59abdbffe5f62fab8634bb
ooxml-ole-object OOXML embedded OLE part: word/embeddings/oleObject1.bin 363008 bytes
emf_00.emf
178c411b16ec3cd6c280c2c883841a531a957f19ed56a58682f277cafe9d61c5
ooxml-emf OOXML EMF part: word/media/image1.emf 245276 bytes