Malicious RTF / .WRI — malware analysis report

Static analysis result for SHA-256 bd63a0586c889502…

MALICIOUS

RTF / .WRI

62.3 KB Created: 2010-05-17 16:22:00
MD5: e4f03a0efe2fee16fef9426a070487b5 SHA-1: ba5ab2ab0188c0f878d01f94745560158ce31645 SHA-256: bd63a0586c8895021fb0b2989dd400b96c7fde623965d3ed5018c6f2d0c5a02e
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file is identified as malicious by ClamAV with the Eicar-Test-Signature, a standard test signature for malware. Static analysis reveals the presence of embedded OLE objects within the RTF structure, a common method for delivering malicious content. The document body is a simple test message, providing no further context.

Heuristics 5

  • ClamAV: Eicar-Test-Signature critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Eicar-Test-Signature
  • Package object class high RTF_OBJCLASS_PACKAGE
    OLE Package object — can wrap arbitrary files
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml}}\paperw11906\paperh16838\margl1701\margr1701\margt1417\margb1417\gutter0\ltrsect

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002f1c.bin
46f77d34ec45f126f58168cdb9273d1bb271de1195877ae9fe2dea0e4afac036
rtf-objdata-decoded RTF \objdata at offset 0x2F1C 475 bytes