The doc file starts malware infection thanks to the internal dll. The trojan is used as a downloader of other payloads such as Cobalt Strike and Ursnif / Gozi.
The loader not only downloads the installer of the legitimate software, but also the to malware, including the RAT that guarantees remote control of the infected PC.