Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 7a7e519f82af8091…

MALICIOUS

RTF / .DOC

31.6 KB Created: 2022-07-13 15:33:00 First seen: 2022-07-14
MD5: 7484e0237ae9f9885c62e3b83cbd87d4 SHA-1: 3c95cdd85609f9464537ec683e458213e8716a9b SHA-256: 7a7e519f82af8091b9ddd14e765357e8900522d422606aefda949270b9bf1a04
62 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF document contains a critical heuristic indicating remote template injection, targeting the URL http://45.197.132.68/public/img/fav.ico. This technique is commonly used to download and execute malicious payloads. The minimal document body content does not provide further context, but the presence of the remote template injection strongly suggests an attempt to compromise the user's system.

Heuristics 2

  • Remote template injection (\*\template → remote URL) critical CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open); destination obfuscated with \uN/\'xx escapes; raw IP host 45.197.132.68.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://45.197.132.68/public/img/fav.ico
    • http://schemas.microsoft.com/office/word/2003/wordml