Malicious Office (OOXML) / .DOC — malware analysis report

Static analysis result for SHA-256 f94cfe3d53b9bfe6…

MALICIOUS

Office (OOXML) / .DOC

351.4 KB Created: 2023-02-28 16:44:00 UTC Authoring application: Microsoft Office Word 12.0000 First seen: 2023-02-28
MD5: 4d93662383a5a4ede5adaa924360b7fc SHA-1: 2156d10195ad7402fba5821886abb12b2f326203 SHA-256: f94cfe3d53b9bfe642318f051d195ab1e443a97301d17e143eb3e19e2744959d
82 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

The sample leverages the CVE-2017-0199 vulnerability, indicated by the OOXML OLE2Link remote loader heuristic, to fetch and execute an external OLE object. The primary IOC is the URL pointing to an XLL file, which is likely the second-stage payload. The document body itself contains no actionable content, but the heuristics strongly suggest a malicious download and execution chain.

Heuristics 3

  • OOXML OLE2Link remote loader — CVE-2017-0199 related high CVE related CVE_2017_0199_RELATED
    Document contains an o:OLEObject Type=Link whose external oleObject relationship points to a remote URL. This is the OOXML OLE2Link activation shape associated with CVE-2017-0199 delivery, but the local file does not expose URL Moniker bytes or a weaponized extension/content type, so the exact CVE cannot be proven statically.
  • External OLE object relationship high OOXML_EXTERNAL_OLE_OBJECT
    Document contains an oleObject relationship whose target is an external HTTP(S) URL. Office resolves this through OLE/object update paths rather than as a normal user-clicked hyperlink.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://www.mediafire.com/file/8qv8nzje8wymhaj/excelDNALibrary-AddIn64.xll/file
    • http://schemas.openxmlformats.org/markup-compatibility/2006
    • http://schemas.openxmlformats.org/officeDocument/2006/relationships
    • http://schemas.openxmlformats.org/officeDocument/2006/math
    • http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing
    • http://schemas.openxmlformats.org/wordprocessingml/2006/main
    • http://schemas.microsoft.com/office/word/2006/wordml
    • https://urlcallinghta.blogspot.com/atom.xml