Malicious RTF — malware analysis report

Static analysis result for SHA-256 83db9f1226cedf2f…

MALICIOUS

RTF

522.5 KB Created: 2013-03-13 17:07:00 First seen: 2015-09-30
MD5: 8a2a8106fed50b3188715d6477e202c0 SHA-1: 8100914fc5e3d5cb4733e660f76769ceb506668f SHA-256: 83db9f1226cedf2f4f6dec05e0a0387f58f136198bb018f7d714603682a3ab6e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The RTF document contains OLE object data and a heuristic firing for a password-protected archive lure, indicating it's designed to trick users into decrypting a payload. An embedded URL was also found, though it appears incomplete. The extracted artifact 'objdata_01_off0003d866.bin' is flagged as a potential shellcode candidate, suggesting it's the malicious payload.

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft In RTF body

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002f06.bin rtf-objdata-decoded RTF \objdata at offset 0x2F06 60541 bytes
SHA-256: e56054d866dadeab2142840d42c4d489f31e495837b09cff50daece51ec601d7
objdata_01_off0003d866.bin rtf-objdata-decoded RTF \objdata at offset 0x3D866 20190 bytes
SHA-256: c69c202140e268818957dd07ba3b5fe226c6591b0bce0281ed6454af78eb5768
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: SC_PEB_ACCESS