Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 9b7c9f7ab50222cc…

MALICIOUS

RTF / .DOC

6.5 KB
MD5: 86bc4732b2c276939c13446451b6f5a3 SHA-1: 270c0ac3b404b36505870a9643884cdac98a1b64 SHA-256: 9b7c9f7ab50222cc0852b989702c623e6a6f3daef1da408cb232bc89f04581fe
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The RTF file contains a critical heuristic indicating remote template injection, pointing to a suspicious URL. This suggests the document is designed to redirect the user to a malicious site. The document body discusses phone usage and radiation, which appears to be a lure to distract from the malicious activity. No scripts were extracted from this sample.

Heuristics 2

  • Remote template injection (\*\template → remote URL) critical CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open); dynamic-DNS / abuse-prone host; target is active/script content, not a .dot template.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://solmo.twilightparadox.com/4a0f2fc36b98452eead58c0a22ccc83d41764ee2/0345304061330.html