Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 accbe536ead9e57b…

MALICIOUS

Office (OOXML) / .DOC

11.5 KB Created: 2018-03-07 09:39:00 UTC Authoring application: Microsoft Office Word 15.0000
MD5: 4bd18d72dec65985525ea4d6b1370a03 SHA-1: 0808de07b0c8cabab19749802287ac17363f0dc2 SHA-256: accbe536ead9e57b36410e8769aeb211ec32419a0e92cf6282d74c0ed53175cb
120 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The sample utilizes OOXML remote template injection, indicating an attempt to load external malicious content. The ClamAV detection as 'Doc.Downloader.Redline' further supports its malicious nature. The embedded URL likely serves as the source for downloading and executing a second-stage payload, characteristic of a downloader malware.

Heuristics 4

  • ClamAV: Doc.Downloader.Redline-9972754-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Redline-9972754-0
  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://cutt.ly/SklJPui) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/webSettings.xml.rels: https://cutt.ly/SklJPui
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2010/wordml
    • http://schemas.microsoft.com/office/word/2012/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroup
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInk
    • http://schemas.microsoft.com/office/word/2006/wordml
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShape