Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 9f04d9ceedd40335…

MALICIOUS

Office (OOXML) / .DOC

79.8 KB Created: 2023-05-24 00:47:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-05-24
MD5: 6605f467f5a976fe1970091bdd5b89cd SHA-1: cbd11d66985e10cb8814624b4430ab5dc05c782f SHA-256: 9f04d9ceedd40335bbe6f337a8e053706b65696329bb045631bfe875800c7e43
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1559.001 Component Object Model

The OOXML document contains heuristics indicating remote template injection and an embedded OLE object, both commonly used to deliver malicious content. The external URL https://kbit.co/oTkb is likely the source of the payload. The presence of these elements strongly suggests an attempt to execute arbitrary code.

Heuristics 4

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://kbit.co/oTkb) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://kbit.co/oTkb
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kbit.co/oTkb
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
dac8f984e4e9dd647e36cb0f568bab0aa9187d55efe78bd82e2f007058c5507f
ooxml-ole-object OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Macro-Enabled_Worksheet4.xlsm 11677 bytes
ooxml_oleobject_01.bin
06569b42119b471f04070b4f9585a263d32198d995692e9fdded813a2a5bdf9c
ooxml-ole-object OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Macro-Enabled_Worksheet1.xlsm 11689 bytes
emf_00.emf
1ab8f5abd845ffd0c61a61bb09bfcf20569b80b4496bccb58c623753cf40485c
ooxml-emf OOXML EMF part: word/media/image1.emf 4056 bytes