Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 63628eab0801688f…

MALICIOUS

Office (OOXML)

105.8 KB Created: 2013-10-10 14:14:00 UTC Authoring application: Microsoft Office Word 14.0000 First seen: 2014-05-13
MD5: 0370ca67728c8c781981186fb8bd19ec SHA-1: 139be6e6830489de81d2429dba1acc361959358f SHA-256: 63628eab0801688ffefd247d5a18be94eea3438373eb254a48c97b1c7911391b
62 Risk Score

Heuristics 2

  • ClamAV: Unix.Trojan.PhpBackdoor-9354530-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Unix.Trojan.PhpBackdoor-9354530-2
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.montessoridolgop.ru/index.php/info/publication/37-psychological-service/251-text251.html In document text (OOXML body / shared strings)
    • http://www.montessoridolgop.ru/index.php/info/publication/37-psychological-service/251-text251.html?tmpl=component&print=1&page=In document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvasIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/markup-compatibility/2006In document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/officeDocument/2006/relationshipsIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/officeDocument/2006/mathIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/wordprocessingml/2006/mainIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordmlIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroupIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInkIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2006/wordmlIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShapeIn document text (OOXML body / shared strings)