Win.Trojan.Webdor-9854571-0 — RTF / .WRI malware analysis

Static analysis result for SHA-256 663703ffa1b2f6f1…

MALICIOUS

RTF / .WRI

297.3 KB Authoring application: Msftedit 5.41.15.1515
MD5: a72ce6962b8f03dae6dd2e9d8c1dfaa4 SHA-1: 0fb609141ea2bddd8ac923fe00a5a7c1945f1f88 SHA-256: 663703ffa1b2f6f145afa279fd129acca138cea93089aa9333d4e5008e098b20
260 Risk Score

Malware Insights

Win.Trojan.Webdor-9854571-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains an embedded OLE object which is identified as a PE executable. Heuristics indicate this is a package object containing a DOS stub, consistent with a trojan. ClamAV signatures confirm the detection of Win.Trojan.Webdor-9854571-0, suggesting the embedded artifact is the primary payload.

Heuristics 6

  • PE header (with DOS stub) in hex data critical RTF_MZ_HEX
    Hex-encoded PE (MZ + DOS stub) found inside RTF — likely an embedded executable payload
  • ClamAV: Win.Trojan.Webdor-9854571-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Webdor-9854571-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Package object class high RTF_OBJCLASS_PACKAGE
    OLE Package object — can wrap arbitrary files
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000003af.bin
2a68f207957a23bd8c4f073b3c2889ee640cebd1ed32740b778287e94473fe11
rtf-objdata-decoded RTF \objdata at offset 0x3AF 145189 bytes
Detection
ClamAV: Win.Trojan.Webdor-9854571-0
Obfuscation or payload: unlikely