Win.Trojan.BAR-1 — RTF malware analysis

Static analysis result for SHA-256 056ee0ed87f5bc19…

MALICIOUS

RTF

9.7 KB Authoring application: Msftedit 5.41.21.2510
MD5: 986fa4c96090ce3817d162d100b841c3 SHA-1: 6708b0626dd5525ed571da53e715ef7eca4b2ace SHA-256: 056ee0ed87f5bc1952b551629f02fc6d210abbd55c0d6ba4c53e6359d2185a0f
140 Risk Score

Malware Insights

Win.Trojan.BAR-1 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains embedded OLE objects, specifically a package object, which is a strong indicator of malicious intent. ClamAV identified the sample as Win.Trojan.BAR-1, suggesting it is a known trojan. The presence of OLE objects points towards exploitation for client execution, likely delivered via spearphishing.

Heuristics 4

  • ClamAV: Win.Trojan.BAR-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.BAR-1
  • Package object class high RTF_OBJCLASS_PACKAGE
    OLE Package object — can wrap arbitrary files
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000ee.bin
2353beca3d09d526a9c30aa327625ae107aa6db9caaf6bdc62413040956c920f
rtf-objdata-decoded RTF \objdata at offset 0xEE 963 bytes