Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 7878431fd8901387…

MALICIOUS

Office (OOXML) / .DOC

38.8 KB Created: 2020-08-14 13:31:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: 46ebab156e28ec6cd687a5a75738c0a2 SHA-1: 12e566c576f7392b456bbf2341677575386d8323 SHA-256: 7878431fd8901387931ed2b1c52bc7def39885104e63fb5245494a91b60ebc47
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document exhibits characteristics of an advance-fee scam, including language about overdue payments, lottery winnings, and fund releases, combined with official-sounding titles and bank names. The presence of embedded URLs, though benign in this case, suggests an attempt to direct the user to external resources. No scripts were extracted from this sample.

Heuristics 4

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml