Malicious Word Document with a Frameset, (Thu, Sep 15th)

This is definitively new, but I did not see this type of document for a while. I spotted a malicious Word OOXML document (the new “.docx” format) that is a simple downloader. Usually, malicious documents contain an embedded file, a VBA macro, or the recent vulnerability MS-MSDT[1]. This time, the document does not contain any malicious code but just refers to a second stage that will be delivered when the document is opened.

Article Link: InfoSec Handlers Diary Blog - SANS Internet Storm Center