Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 3342d74ec2b0c732…

MALICIOUS

RTF / .DOC

1.89 MB Created: 2021-11-08 16:01:00 First seen: 2022-05-18
MD5: 7e088808e52ed5eb88d4a2df6c77cfae SHA-1: c43241f4e342dfac9bf3c119e3792b937409fe06 SHA-256: 3342d74ec2b0c7324d6cc94a6e9989f002ec02b43927fe6b0951e160829843be
62 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The RTF file contains a critical heuristic indicating remote template injection, pointing to a suspicious URL. This suggests the document is designed to lure the user into downloading and executing a secondary payload from the specified remote resource. The embedded URL is the primary indicator of compromise.

Heuristics 2

  • Remote template injection (\*\template → remote URL) critical CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open); destination obfuscated with \uN/\'xx escapes; dynamic-DNS / abuse-prone host; target is active/script content, not a .dot template.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://wrd.intector.xyz/39Hq4vSPhlIwdUP9/naLhrcrCK8cV8Imf.php
    • http://schemas.microsoft.com/office/word/2003/wordml