Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 95004ce72c4126ab…

MALICIOUS

Office (OOXML) / .DOC

10.1 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: 9e384c7249745f54b64792d2f8b5b53c SHA-1: b8b7fe86c35e65cb553ab49688a25032c55ac8f1 SHA-256: 95004ce72c4126abf44c49586cd277fcdad1ff2b2d463ecae509997786c24e2f
122 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 Command and Scripting Interpreter T1071.001 Application Layer Compromise T1566.001 Phishing

The heuristic detections, specifically OOXML_REMOTE_TEMPLATE and CLAMAV_DETECTION, strongly indicate a remote template injection attack. The document leverages a URL to download a macro-enabled template, which, upon execution, likely initiates the download and execution of a secondary payload. The document body excerpt confirms this behavior, referencing the same URL repeatedly and highlighting the vulnerability. The presence of the ClamAV detection further solidifies the malicious nature of the file.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://bit.ly/3wf712V) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://bit.ly/3wf712V
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml
    • https://bit.ly/3wf712V