Office (OOXML) / .DOC static analysis report

Static analysis result for SHA-256 c1934058fa87a23e…

SUSPICIOUS

Office (OOXML) / .DOC

53.8 KB Created: 2022-08-15 17:29:00 UTC Authoring application: Microsoft Office Word 16.0000 First seen: 2022-09-23
MD5: a0d07d0277301424f630eb4f7663c76e SHA-1: 782dcc4d41bb55b82177fba6042e38e5f0ec2736 SHA-256: c1934058fa87a23ea9fc249791ee3032ded62dea5555eecb8f2c243701be221d
30 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1566.001 Spearphishing Attachment

The document contains external hyperlinks to 'about:blank' and triggers a heuristic for callback phishing or tech-support scams by presenting a phone number lure. The primary goal appears to be social engineering the user into initiating a phone call, likely for financial fraud or credential theft.

Heuristics 3

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • External hyperlinks (5) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 5 external hyperlinks — clickable URLs are stored as external relationships. First target: about:blank
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas Document hyperlink
    • http://schemas.microsoft.com/office/drawing/2014/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2015/9/8/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2015/10/21/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/9/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/10/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/11/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/12/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/13/chartexDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/5/14/chartexDocument hyperlink
    • http://schemas.openxmlformats.org/markup-compatibility/2006Document hyperlink
    • http://schemas.microsoft.com/office/drawing/2016/inkDocument hyperlink
    • http://schemas.microsoft.com/office/drawing/2017/model3dDocument hyperlink
    • http://schemas.microsoft.com/office/2019/extlstDocument hyperlink
    • http://schemas.openxmlformats.org/officeDocument/2006/relationshipsDocument hyperlink
    • http://schemas.openxmlformats.org/officeDocument/2006/mathDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingDrawingDocument hyperlink
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawingDocument hyperlink
    • http://schemas.openxmlformats.org/wordprocessingml/2006/mainDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2012/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2018/wordml/cexDocument hyperlink
    • http://schemas.microsoft.com/office/word/2016/wordml/cidDocument hyperlink
    • http://schemas.microsoft.com/office/word/2018/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2020/wordml/sdtdatahashDocument hyperlink
    • http://schemas.microsoft.com/office/word/2015/wordml/symexDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingGroupDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingInkDocument hyperlink
    • http://schemas.microsoft.com/office/word/2006/wordmlDocument hyperlink
    • http://schemas.microsoft.com/office/word/2010/wordprocessingShapeDocument hyperlink
    • https://cdn.asp.events/CLIENT_NASBA_287596D2_5056_B733_49DFF69B632BDF66/sites/LearningMarket/media/Documents/2019-standards-and-fos/Fields-of-Study-Document---December-2019.pdfDocument hyperlink