Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 78b9d644a39f8479…

MALICIOUS

Office (OOXML) / .DOC

3.60 MB Created: 2011-03-30 02:05:00 UTC Authoring application: Microsoft Office Word 14.0000
MD5: fe4dd316363d3631c83c2995dd3775f4 SHA-1: a06850be4f2af8f40f796666459898b5740982b5 SHA-256: 78b9d644a39f8479e1dfa7ac19e1f3bc66a2f3ea517727903383b6a365b8f8f4
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains heuristics indicating the use of remote template injection and external relationships, both pointing to the URL http://beilksa.scienceontheweb.net/cookie/select/log/tmp?q=6. This suggests the document is designed to lure the user into downloading and executing a malicious payload from this external source, likely as part of a phishing campaign.

Heuristics 3

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (http://beilksa.scienceontheweb.net/cookie/select/log/tmp?q=6) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: http://beilksa.scienceontheweb.net/cookie/select/log/tmp?q=6
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://beilksa.scienceontheweb.net/cookie/select/log/tmp?q=6