Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 65506fa34684350f…

MALICIOUS

Office (OOXML)

590.2 KB Created: 2012-01-29 18:16:03 UTC Authoring application: Microsoft Office PowerPoint 12.0000 First seen: 2012-07-12
MD5: f7ad35a8a609813c0dd17b0978135ded SHA-1: 34f3689f3d05d472852b093fc7ef33f2dafcfb20 SHA-256: 65506fa34684350ff5b0fb271a071da7d7d49a3aa730d624665833da58b752d0
70 Risk Score

Heuristics 3

  • ClamAV: Html.Spyware.IMG-6 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Html.Spyware.IMG-6
  • External hyperlinks (6) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 6 external hyperlinks — clickable URLs are stored as external relationships. First target: http://www.milesfrases.com/
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ciudad.com.ar/ar/popunder/p_submit.asp?site=personales.ciudad.com.ar In document text (OOXML body / shared strings)
    • http://www.milesfrases.com/Document hyperlink
    • http://www.milespowerpoints.com/Document hyperlink
    • http://www.frasesfrases.es/Document hyperlink
    • http://milespowerpoints.ourtoolbar.com/Document hyperlink
    • http://www.milespostales.com/Document hyperlink
    • http://www.milesvideos.com/Document hyperlink
    • http://ns.adobe.com/xap/1.0/In document text (OOXML body / shared strings)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In document text (OOXML body / shared strings)
    • http://purl.org/dc/elements/1.1/In document text (OOXML body / shared strings)
    • http://ns.adobe.com/xap/1.0/mm/In document text (OOXML body / shared strings)
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In document text (OOXML body / shared strings)
    • http://ns.adobe.com/tiff/1.0/In document text (OOXML body / shared strings)
    • http://ns.adobe.com/exif/1.0/In document text (OOXML body / shared strings)
    • http://ns.adobe.com/photoshop/1.0/In document text (OOXML body / shared strings)