MALICIOUS
202
Risk Score
Heuristics 5
-
ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
-
\objupdate forces OLE activation high RTF_OBJUPDATERTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
-
OLE object data medium RTF_OBJDATARTF contains 10 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off00002a87.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x2A87 | 21057 bytes |
SHA-256: 9d433b43bf9ffa8fd9249586fcf979815f79ecdcd86006714e7925f4eb8766cf |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_01_off00012896.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x12896 | 21057 bytes |
SHA-256: 538a3b569f84b7355267ae1cc62e7e6ee8e3e76dba90a955436023f838ee6388 |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_02_off000226a7.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x226A7 | 21057 bytes |
SHA-256: 4facd55c64952ce9a60389bbc086034aacb14175551112cbe42ee3ea98ed0a44 |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_03_off000324b8.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x324B8 | 21057 bytes |
SHA-256: ccaf39598108876030e15391d64299e9028f30cc8981d6b2b02f14774903385c |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_04_off000422c9.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x422C9 | 21057 bytes |
SHA-256: 36559b819d634df39420732799b6c3d74291cb4c46e3884bd579bb38154ff4ae |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_05_off000520da.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x520DA | 21057 bytes |
SHA-256: 00f2a7e10dbf25f5c0bf9420318100096495ee839b8c4ee89e20b94a5e6cdf0e |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_06_off00061eeb.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x61EEB | 21057 bytes |
SHA-256: 616a7010f2c36904b049a4a3069ccc3d82146a16f5ef041fce7599d5eae5d52e |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_07_off00071cfc.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x71CFC | 21057 bytes |
SHA-256: 7a8acd6f7726178557028081807136400aefd20f8f66a73c057109e63f369562 |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_08_off00081b0d.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x81B0D | 21057 bytes |
SHA-256: 1eb59c018ad36ec61e3c381cd532a18f3b76cb9e43cb68dc719a0ddc4aacf7b9 |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
objdata_09_off0009191e.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x9191E | 21057 bytes |
SHA-256: 011682730876c528dd050fb4f7a2a66255704d93823f3063c704efbf2db90159 |
|||
|
Detection
ClamAV:
Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload:
unlikely
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.