Rtf.Dropper.Agent-6827592-0 — RTF malware analysis

Static analysis result for SHA-256 bea774bb1de566f1…

MALICIOUS

RTF

42.1 KB First seen: 2019-05-16
MD5: a77bb08918ea1dd19c6f1f9733039d96 SHA-1: fea6835a403a67b79522d502754d51863dcf20aa SHA-256: bea774bb1de566f14f46b36c84e1a04cc01889bf697628d6024fde8e0b012554
200 Risk Score

Malware Insights

Rtf.Dropper.Agent-6827592-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains OLE objects that are automatically linked and updated, triggering the execution of embedded code. A URL Moniker related heuristic indicates that the OLE object attempts to download a payload from the obfuscated URL. ClamAV identifies the file as Rtf.Dropper.Agent-6827592-0, suggesting a dropper functionality.

Heuristics 5

  • URL Moniker in RTF OLE object high CVE related RTF_URL_MONIKER_RELATED
    RTF contains a URL Moniker GUID in OLE object context, but no decoded remote target was confirmed. Treat as related OLE2Link attack-surface evidence rather than proof of CVE-2017-0199 exploitation.
  • ClamAV: Rtf.Dropper.Agent-6827592-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Dropper.Agent-6827592-0
  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000546a.bin rtf-objdata-decoded RTF \objdata at offset 0x546A 9477 bytes
SHA-256: 080880572caf871be5175fdf2273d0197d87b5cd617a230b1b22beef9ccf550d