Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 a5ac36f6a99ec92d…

MALICIOUS

Office (OOXML) / .DOC

22.7 KB Created: 2023-08-06 18:37:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-08-10
MD5: 228f3b042d432eb4ffa95a97ca6eea4a SHA-1: 677e75d0a274b8bf9f71e01c6de0d10761338b35 SHA-256: a5ac36f6a99ec92dedf0f7540aca80496e33a976e9a74f74f81c46dd0b6daab7
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1559 Component Object Model Hijacking

The OOXML document contains heuristics indicating remote template injection and external relationship manipulation, both pointing to the loading of external content. The primary suspicious URL identified is https://emojied.net/😂😡🙂🙊😧🙂, which is likely used to deliver a malicious payload. No scripts were extracted, and the document body was minimal, making the analysis reliant on the OOXML structure and embedded URLs.

Heuristics 3

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://emojied.net/😂😡🙂🙊😧🙂) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://emojied.net/😂😡🙂🙊😧🙂
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://emojied.net/😂😡🙂🙊😧🙂
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml