Been given a .docx file to check whether it has a virus or something, ran McAfee and SuperAntiSpyware on it and results came back negative so I though it was good and proceeded to open it, just a file with some text, few .jpg and .png files and a little draw on there.
Out of curiosity uploaded it to VirusTotal and it says it's clean too but in the behaviour tab it seems like it opens a lot of files, write in some others and opens and sets some keys in the Windows Registry, overall on \Microsoft\Office...
Also says it runs this "...\Office15\WINWORD.EXE /Automation -Embedding, creates some mutexes (I don't know what that is)
Behaviour tag clams it calls wmi
I replaced the extension to .zip so I could see those .xml files in there and after reading through them all can't really tell they are good or no, they appear to be.
Is a .docx file capable of setting keys in the registry? I only noticed the search sidebar panel in Word was closed while it's usually out, I thought I must've closed it last time.
Maybe that site uses some virtualization and it causes that for some reason?
I restored the system with a image I got so that's fixed now but I'm curious because I usually just run the AV and go on with life just like that and I don't have a file without personal data to try.
If there is a possibility someone here knows better and have the time to check it out, please, I can upload it somewhere so that anyone can see them
Thanks in advance.
EDIT:
Just created another .docx file from LibreOffice with a table, some text and few pics on it and it just creates same amount of .xml files, they look pretty much the same so after uploading it to VirusTotal, this new file also have that behavior tab with same paths and tags as the one I was given in the first place.
I assume it's just the way it handles it or something but the file is clear.