Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 d523606b3e494432…

MALICIOUS

Office (OOXML) / .DOC

97.8 KB Created: 2023-05-24 00:47:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-05-31
MD5: 3c2154f7a57d029a358ca79570235c06 SHA-1: a925f4a8f7a19442df0778907f2649e6d12e38f2 SHA-256: d523606b3e494432753a1379b994e1a48e73508b4b41744069703e74819dce6e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution T1559.001 Component Object Model Hijacking

The OOXML document exhibits characteristics of remote template injection and contains an embedded OLE object, both of which are indicative of malicious intent. The presence of the URL https://kbit.co/TCDv, flagged as unknown reputation, strongly suggests it is used to download and execute a secondary payload. The combination of these factors points towards a downloader or dropper mechanism.

Heuristics 4

  • Remote template injection high OOXML_REMOTE_TEMPLATE
    Document references a remote template URL (https://kbit.co/TCDv) — a common remote-template-injection vector used by Hancitor, Emotet and many phishing campaigns. Word can fetch and apply the remote template; macros in that template may execute depending on Office policy and trust state.
  • External relationship medium OOXML_EXTERNAL_REL
    External target in word/_rels/settings.xml.rels: https://kbit.co/TCDv
  • Embedded OLE object medium OOXML_OLE_OBJECT
    Document contains an embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://kbit.co/TCDv
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
ooxml_oleobject_00.bin
dac8f984e4e9dd647e36cb0f568bab0aa9187d55efe78bd82e2f007058c5507f
ooxml-ole-object OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Macro-Enabled_Worksheet4.xlsm 11677 bytes
ooxml_oleobject_01.bin
06569b42119b471f04070b4f9585a263d32198d995692e9fdded813a2a5bdf9c
ooxml-ole-object OOXML embedded OLE part: word/embeddings/Microsoft_Office_Excel_Macro-Enabled_Worksheet1.xlsm 11689 bytes
emf_00.emf
1ab8f5abd845ffd0c61a61bb09bfcf20569b80b4496bccb58c623753cf40485c
ooxml-emf OOXML EMF part: word/media/image1.emf 4056 bytes