Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 c777b34dceae0341…

MALICIOUS

Office (OOXML) / .DOC

18.2 KB Created: 2023-06-11 02:09:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-06-19
MD5: 2ac22545e32374cc0903293498fafe11 SHA-1: 2c7ae141086b2c93faea07ba112a3669b35a779b SHA-256: c777b34dceae03414ca247b555517f985d291b051a52b9067d70b936ef251612
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The OOXML document contains a heuristic firing for remote template injection, pointing to the URL https://han.gl/OxwOLg. This indicates the document is designed to fetch and execute content from an external source. The presence of an external relationship further supports the likelihood of malicious content being loaded. The primary goal appears to be downloading and executing a secondary payload.

Heuristics 3

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://han.gl/OxwOLg) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://han.gl/OxwOLg
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://han.gl/OxwOLg
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml