Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 a1b230266443fcb3…

MALICIOUS

Office (OOXML) / .DOC

10.1 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 12.0000
MD5: 68fa428c624f214fd1f4f5613d05f0b3 SHA-1: bf2a3e1eaf3a6195e8a593a5b6c6a37bf61e9986 SHA-256: a1b230266443fcb32c1e168d8bd522ee1929424a168d11f74fc8608c19b27258
122 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The file exhibits characteristics of a malicious document, specifically triggering heuristics for remote template injection and external relationships. The ClamAV detection further supports its malicious nature. The embedded URL, although marked as confirmed benign in this context, is often used in such lures. The primary attack pattern involves tricking the user into fetching a secondary payload.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://is.gd/du7JJm) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
    URL https://is.gd/du7JJm
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://is.gd/du7JJm
    URL https://is.gd/du7JJm
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — context-specific rules above attribute URLs they actually evaluated; this rule lists URLs that were present in the bytes but were not otherwise tied to a specific finding.
    URL http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml