Img.Dropper.PhishingLure-6329861-0 — Office (OOXML) malware analysis

Static analysis result for SHA-256 83819e49b8f16056…

MALICIOUS

Office (OOXML)

238.0 KB Created: 2017-04-26 13:52:00 UTC Authoring application: Microsoft Office Word 15.0000 First seen: 2021-01-23
MD5: 35e80a69284ce2a9a74a52a9173692b6 SHA-1: 788f42529eb6b5403eb9e4d0bfbe794122b71425 SHA-256: 83819e49b8f16056ffc781c331254336acc02217aa899eef57aef8bbd9822322
144 Risk Score

Malware Insights

Img.Dropper.PhishingLure-6329861-0 · confidence 90%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is detected as Img.Dropper.PhishingLure-6329861-0 by ClamAV, indicating it's a dropper designed for phishing lures. It contains an embedded OLE object which, based on heuristic firings, likely hosts URLs pointing to a secondary payload. The URLs http://akashbaninews.com/therp.txt and http://akashbaninews.com/pap1.txt are strong indicators of this malicious behavior.

Heuristics 4

  • ClamAV: Img.Dropper.PhishingLure-6329861-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Img.Dropper.PhishingLure-6329861-0
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Payload URL recovered from embedded OLE object (3 URLs) info OOXML_EMBEDDED_OBJECT_URL
    An embedded OLE object (xl/word/ppt embeddings) carries a next-stage download URL in its Ole10Native/Package stream — stored literally (incl. UTF-16) or base64-encoded — which the package-level URL sweep does not see. Surfaced as an IOC; self-validating (only real payload hosts).
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://akashbaninews.com/therp.txt In document text (OOXML body / shared strings)
    • http://akashbaninews.com/pap1.txtIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvasIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/markup-compatibility/2006In document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/officeDocument/2006/relationshipsIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/officeDocument/2006/mathIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingIn document text (OOXML body / shared strings)
    • http://schemas.openxmlformats.org/wordprocessingml/2006/mainIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordmlIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2012/wordmlIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroupIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInkIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2006/wordmlIn document text (OOXML body / shared strings)
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShapeIn document text (OOXML body / shared strings)
    • http://www.google.com/search?q=In document text (OOXML body / shared strings)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin ooxml-ole-object OOXML embedded OLE part: word/embeddings/oleObject1.bin 642560 bytes
SHA-256: 67366a45e1cb81d9c99eff3a1e76248bb5d383443614246fbf888ed46acbd952
emf_00.emf ooxml-emf OOXML EMF part: word/media/image1.emf 3576 bytes
SHA-256: 3e7d47ac6028910c5f46ac075a6c021163a8f00bd32164a5551afdfd9c33220f
Detection
ClamAV: Img.Dropper.PhishingLure-6329861-0
Obfuscation or payload: unlikely