Malicious RTF — malware analysis report

Static analysis result for SHA-256 176df5f6647d9a8e…

MALICIOUS

RTF

3.3 KB Authoring application: Msftedit 5.41 First seen: 2015-10-05
MD5: df98e116625030cb7825437670e5a140 SHA-1: 6760fb998dc1bf8289097b78324aa6c73a33b7dd SHA-256: 176df5f6647d9a8ea02b44448732d9666c50386293c45f2c7912e3a46ee4d1a1
60 Risk Score

Heuristics 2

  • MSCOMCTL.ListView — CVE-2012-0158 high CVE related CVE_2012_0158
    RTF \objdata decodes to OLE data containing the MSCOMCTL.ListView — CVE-2012-0158 CLSID — the vulnerable control/moniker is embedded directly in the document's object stream, the delivery shape of this exploit. RTF objects auto-render when Word opens the file.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000c0.bin rtf-objdata-decoded RTF \objdata at offset 0xC0 1594 bytes
SHA-256: 42150ab4ca44603c9e7405b1bdd8973f60e28517629eb0f46ca68189c701fca5