Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 57deff512cd7491f…

MALICIOUS

Office (OOXML)

34.4 KB Created: 2013-01-08 13:39:00 UTC Authoring application: Microsoft Office Word 16.0000
MD5: aeef8c08b1184be67fc3ecac15e12f4e SHA-1: a8bd3efc334df044cd52fcfb837cbda18345557a SHA-256: 57deff512cd7491f0a2181bb627b260aa5e73c37e8520e36a789b6fe4a12fa59
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The sample is an OOXML document that exhibits high-risk heuristics for remote template injection and external hyperlinks. These indicators suggest the document is designed to load external resources, potentially leading to the execution of malicious code or redirection to a compromised site. The presence of external URLs, even if some are benign, points towards an attempt to establish a connection to a remote resource for malicious purposes.

Heuristics 4

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (http://fcahome/readingrm/handbook/FCA Regulation/Forms/template.dotx) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: http://fcahome/readingrm/handbook/FCA Regulation/Forms/template.dotx
  • External hyperlinks (5) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 5 external hyperlinks — clickable URLs are stored as external relationships. First target: http://ww3.fca.gov/readingrm/handbook/FCA Regulation/612.2140.docx
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ww3.fca.gov/readingrm/handbook/FCA
    • http://fcahome/readingrm/handbook/FCA
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.microsoft.com/office/drawing/2014/chartex
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartex
    • http://schemas.microsoft.com/office/drawing/2015/10/21/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/9/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/10/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/11/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/12/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/13/chartex
    • http://schemas.microsoft.com/office/drawing/2016/5/14/chartex
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.microsoft.com/office/drawing/2016/ink
    • http://schemas.microsoft.com/office/drawing/2017/model3d
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2016/wordml/cid
    • http://schemas.microsoft.com/office/word/2015/wordml/symex
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape