Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 d040e890b58aad20…

MALICIOUS

Office (OOXML) / .DOC

13.1 KB Created: 2021-06-11 13:07:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-07-17
MD5: e9fb71dd600d96ec09b6aa7143b43a67 SHA-1: aa37c5659c8edde33a52a74e91b461e27295c6ff SHA-256: d040e890b58aad20ff1c101a2b4ff4e90b1d18f835cb223a4a8ce4ee13a1f99e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The OOXML document contains heuristics indicating remote template injection and an external relationship, suggesting it attempts to load content from an external source. The embedded URL points to a suspicious domain, likely serving as a lure for a malicious payload. No scripts were extracted, but the presence of an OLE object further supports a malicious intent.

Heuristics 4

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://e.vg/rFkRXoxf) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://e.vg/rFkRXoxf
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://e.vg/rFkRXoxf
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
f27b400c137ad6a2cffea5f0a7d954327e2eead540a4b8856ab1962089261f3f
ooxml-ole-object OOXML embedded OLE part: word/embeddings/oleObject1.bin 5632 bytes