Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 801866347c9b2110…

MALICIOUS

Office (OOXML) / .DOC

41.8 KB Created: 2018-02-20 23:57:00 UTC Authoring application: Microsoft Office Word 14.0000
MD5: 9f5ba55b57e8879ce83e30e667a2f773 SHA-1: 5bfcc776124a0acf0cce8a13a44e09576fa6836a SHA-256: 801866347c9b21104cce1a80b2a77015b88d9486b19e6133345458fe2a7d3345
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The file is detected as a dropper by ClamAV, indicating its primary purpose is to download and execute other malware. While no specific document body content or scripts were provided for analysis, the heuristic firing strongly suggests a malicious dropper functionality. The embedded URLs are all confirmed benign schema references and do not provide further IOCs.

Heuristics 2

  • ClamAV: Doc.Dropper.Agent-6457054-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6457054-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape