Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 9e3b9c53eb36e3ed…

MALICIOUS

Office (OOXML) / .DOC

10.1 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: 94acea4fc503e1262d8c08c7122531c7 SHA-1: dbd4b7c4b7bb18568881cfbea8d214c8b9b720e8 SHA-256: 9e3b9c53eb36e3ed1630f87b369e72c4b03a28802922924a153245b1a5152663
122 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The file exhibits characteristics of a malicious document downloader, specifically triggering heuristics for remote template injection and external relationships. The ClamAV detection further supports its malicious nature. The primary IOC is the remote template URL, which is likely used to fetch and execute a secondary payload.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://cutt.ly/2ntJmOt) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
    URL https://cutt.ly/2ntJmOt
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://cutt.ly/2ntJmOt
    URL https://cutt.ly/2ntJmOt
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml