Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 885c89c79cbfd9fe…

MALICIOUS

Office (OOXML) / .DOC

50.0 KB Created: 2020-02-25 05:41:00 UTC Authoring application: Microsoft Office Word 14.0000
MD5: 31f38ce02cda05dced5b9aff990a7578 SHA-1: e4ff2e9d32babffcf946ee6824181c90de2437af SHA-256: 885c89c79cbfd9fe360ae6b456bd42f0b388e45c3bf9b414778b6f098f5056a5
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The file is identified as malicious due to the presence of heuristics indicating remote template injection and external relationships pointing to a suspicious URL. This suggests the document is designed to download and execute additional malicious content from the external source. The document body contains text related to Ukrainian legislation, which may serve as a lure.

Heuristics 3

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (http://fidel.freedynamicdns.org/apache2/log/cyxyAB.dot) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: http://fidel.freedynamicdns.org/apache2/log/cyxyAB.dot
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://fidel.freedynamicdns.org/apache2/log/cyxyAB.dot
    • http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape