Malicious RTF — malware analysis report

Static analysis result for SHA-256 0f29646df2f7b48f…

MALICIOUS

RTF

961.6 KB Created: 2018-06-19 11:49:00 First seen: 2021-02-23
MD5: 31bcf3be8ba1aa74ca80ba4141e304dc SHA-1: 373c887fb9ea410f816e3e2dd4c42dd6fdc2e2be SHA-256: 0f29646df2f7b48f52df5e86082df27dd4ab3bd529fa4364a08f0c0ac6f10f3a
242 Risk Score

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Generic-6834349-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Generic-6834349-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003d92.bin rtf-objdata-decoded RTF \objdata at offset 0x3D92 35899 bytes
SHA-256: 34a1e285761aa1677a2cf9e605232f3ce7bc02b61af05f1778e95d15aa066029
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_01_off0001aea4.bin rtf-objdata-decoded RTF \objdata at offset 0x1AEA4 35899 bytes
SHA-256: b3436bbecedf660652e3cd930631d35a0d4ae8cb2ac95ada4353eaeb9f989b0e
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_02_off00031fb6.bin rtf-objdata-decoded RTF \objdata at offset 0x31FB6 35899 bytes
SHA-256: 36440c7f51133d82aacdec5de9d5170c941fef9dcea0836cd566920429076250
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_03_off000490c8.bin rtf-objdata-decoded RTF \objdata at offset 0x490C8 35899 bytes
SHA-256: 74a576359b26d9855e4cc638f8d52ecd68b2ca82166352565116bac2e466efda
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_04_off000601da.bin rtf-objdata-decoded RTF \objdata at offset 0x601DA 35899 bytes
SHA-256: 14d99de7262fd3c7d7e8285db5ad57f53ae3cd31624bc06032957c7d104e7767
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_05_off0007811f.bin rtf-objdata-decoded RTF \objdata at offset 0x7811F 35899 bytes
SHA-256: b4f9bd900345700d7b45aa33e46fb09a3140d6ed58e462572552d4dc53c4d648
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_06_off0008f24f.bin rtf-objdata-decoded RTF \objdata at offset 0x8F24F 35899 bytes
SHA-256: 8cecee8786478b751de3651f12cb1ad7128bb9fd36a1cb18e9958018df9a0abf
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_07_off000a6381.bin rtf-objdata-decoded RTF \objdata at offset 0xA6381 35899 bytes
SHA-256: 6eab7d45cf6bab22bd923009866db9e47b903841138472def25ff7db5cbd5141
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_08_off000bd4b3.bin rtf-objdata-decoded RTF \objdata at offset 0xBD4B3 35899 bytes
SHA-256: 2fd3e51477dc702f83eddc0702e2c7668ebc5e0c8da2dd5cf588a390e83f8883
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_09_off000d45e5.bin rtf-objdata-decoded RTF \objdata at offset 0xD45E5 35899 bytes
SHA-256: c7830b40b482bef6cef8fa49b92c7f6478c9d0e838dc38d496d8101816b278dc
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely