Rtf.Dropper.Agent-9369854-0 — RTF malware analysis

Static analysis result for SHA-256 74aa6fff407dee85…

MALICIOUS

RTF

618.1 KB Created: 2020-07-13 17:14:00
MD5: b88b941590b8f4c40effb8503381d913 SHA-1: 85004c1436b8be7c23ea0cf639ce70714c79107d SHA-256: 74aa6fff407dee851f224329489232a8e7f2d6046aaff3c9cebfff81b7d5db22
144 Risk Score

Malware Insights

Rtf.Dropper.Agent-9369854-0 · confidence 95%

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The file is identified as malicious by ClamAV with the signature Rtf.Dropper.Agent-9369854-0. Static analysis reveals the presence of embedded OLE objects and an \objupdate directive, strongly suggesting an exploit or dropper functionality. The embedded OLE objects are likely used to deliver a secondary payload.

Heuristics 6

  • ClamAV: Rtf.Dropper.Agent-9369854-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Dropper.Agent-9369854-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00010ff9.bin
c93d8d24c28019d4563c6d62c42d02544bfef00f5f1c6039560701b494343a64
rtf-objdata-decoded RTF \objdata at offset 0x10FF9 274648 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
objdata_01_off000971cf.bin
6343cda1504f594e5e3284edab0f928b3d394e5ea2e5b7ff4964608d26ac88dc
rtf-objdata-decoded RTF \objdata at offset 0x971CF 6847 bytes
objdata_02_off000971e9.bin
529d240293f9f5d60775624144a72c9e50e506cb5f619a21610e5297b93ce75c
rtf-objdata-decoded RTF \objdata at offset 0x971E9 6843 bytes