Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 b1b2c45d348b6edd…

MALICIOUS

Office (OOXML) / .DOC

79.8 KB Created: 2023-05-24 00:47:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-05-26
MD5: 04f486e82249a607bd17b5f1a991ba34 SHA-1: 07652ae904b82242671b9b3a48eba278d63d440e SHA-256: b1b2c45d348b6eddafc31b5a33660a21bda65c8c51684a70c58486992c0ab131
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The OOXML document contains heuristics indicating remote template injection and an embedded OLE object, both of which are commonly used to deliver malicious payloads. The external relationship points to 'https://kbit.co/vlUj', a likely indicator of a malicious URL used for exploitation or payload delivery. No scripts were extracted from this sample.

Heuristics 4

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://kbit.co/vlUj) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://kbit.co/vlUj
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kbit.co/vlUj
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
dac8f984e4e9dd647e36cb0f568bab0aa9187d55efe78bd82e2f007058c5507f
ooxml-ole-object OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Macro-Enabled_Worksheet4.xlsm 11677 bytes
ooxml_oleobject_01.bin
06569b42119b471f04070b4f9585a263d32198d995692e9fdded813a2a5bdf9c
ooxml-ole-object OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Macro-Enabled_Worksheet1.xlsm 11689 bytes
emf_00.emf
1ab8f5abd845ffd0c61a61bb09bfcf20569b80b4496bccb58c623753cf40485c
ooxml-emf OOXML EMF part: word/media/image1.emf 4056 bytes