Doc.Downloader.Redline-9972754-0 — Office (OOXML) / .DOC malware analysis

Static analysis result for SHA-256 749fb38cd9401137…

MALICIOUS

Office (OOXML) / .DOC

10.1 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: ad8d2142b2257f54b5fa8b0343475588 SHA-1: dcca1ada5f9cfd5d2df2a5ac0a6b103a446cc922 SHA-256: 749fb38cd940113757626a3b0988ffd50f1a9dec1fabe7cf70ed7cc26162de4e
122 Risk Score

Malware Insights

Doc.Downloader.Redline-9972754-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file exhibits critical heuristic firings for remote template injection and external relationships, indicating an attempt to load external content. The ClamAV detection explicitly names this as Doc.Downloader.Redline-9972754-0, a known downloader family. The primary IOC is the external URL used for the template injection, which likely serves as the initial stage for downloading a secondary payload.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://pixi-url.herokuapp.com/7d243f97222f) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://pixi-url.herokuapp.com/7d243f97222f
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://pixi-url.herokuapp.com/7d243f97222f
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml