Malicious RTF — malware analysis report

Static analysis result for SHA-256 cd83ade470d06595…

MALICIOUS

RTF

14.10 MB Created: 2018-01-23 22:58:00 First seen: 2022-08-02
MD5: 1dd6049d83fae48c61ec21957f9e4538 SHA-1: 29509ee419482cc7dd88160e1b59817010343340 SHA-256: cd83ade470d06595302066a5fe404dfd43616dc627825fc7ea974eb98f4bec65
842 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 Command and Scripting Interpreter: JavaScript T1190 Exploit Public-Facing Application

This RTF document exploits CVE-2023-21716 via an anomalous font table to achieve code execution. It contains a PHP webshell and references to tools like cmd.exe, certutil, bitsadmin, and PowerShell, indicating a likely intent to download and execute further payloads or establish remote code execution. The document body also contains lures for remote support and phone scams, suggesting a multi-stage attack.

Heuristics 23

  • CVE-2023-21716 — \fonttbl with 32768 entries critical CVE exact CVE_2023_21716
    RTF font table contains 32768 font entries, which is highly anomalous — CVE-2023-21716 triggers a heap buffer overflow in Word's RTF font table parser when the number of entries is very large (exploitable from ~32768 entries). This document is suspicious.
  • URL Moniker in RTF OLE object high CVE related RTF_URL_MONIKER_RELATED
    RTF contains a URL Moniker GUID in OLE object context, but no decoded remote target was confirmed. Treat as related OLE2Link attack-surface evidence rather than proof of CVE-2017-0199 exploitation.
  • PHP webshell / backdoor source critical WEBSHELL_PHP
    The file contains PHP server-side code with the signature of a webshell/backdoor (request input fed to a command/code-exec sink with a decoder/second sink (RCE backdoor)). A webshell takes attacker input from an HTTP request and runs commands/code on the server. Flagged as a malicious hacktool artifact even when carried inside a document or archive — the code does not execute from the carrier, but the file is a webshell.
  • Reference to WinExec API high SC_STR_WINEXEC
    Reference to WinExec API
  • Reference to CreateProcess API high SC_STR_CREATEPROCESS
    Reference to CreateProcess API
  • Reference to ShellExecute API high SC_STR_SHELLEXEC
    Reference to ShellExecute API
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to PowerShell high SC_STR_POWERSHELL
    Reference to PowerShell
  • Reference to Windows Script Host high SC_STR_WSCRIPT
    Reference to Windows Script Host
  • Reference to certutil (download/decode) high SC_STR_CERTUTIL
    Reference to certutil (download/decode)
  • Reference to bitsadmin (download) high SC_STR_BITSADMIN
    Reference to bitsadmin (download)
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1167KB of hex-encoded data inside \objdata sections — may hide a payload
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • x86 push-string-call medium SC_PUSH_STRING
    Shellcode-style PUSH imm32 sequence builds an execution, network, or Windows API string on the stack
    Disassembly hidden — these bytes score as data, not coherent x86 code (3/9 branch targets land on an instruction boundary (33% coherence)).
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.schmidhorst.de/regdom In RTF body
    • http://www.delphipraxis.net/118485-ermitteln-ob-32-bit-oder-64-bit-betriebssystem.htmlIn RTF body
    • http://www.ebay.com:verify@www.spion.comIn RTF body
    • http://www.windowspro.de/tipp/einfaches-single-sign-workgroups-und-mit-samba-durch-cmdkeyIn RTF body
    • http://www.computer-engineering.orgIn RTF body
    • http://www.softwareok.de/?Microsoft/DontSleepIn RTF body
    • https://www.opautoclicker.com/In RTF body
    • http://www.tnk-bootblock.co.uk/prods/miscIn RTF body
    • http://www.docu-track.com/home/prod_user/PDF-XChange_Tools/pdfx_viewer/In RTF body
    • http://www.it-techblog.de/vista-workshop-notebooks-drahtlos-ad-hoc-vernetzen/07/2007/In RTF body
    • http://jens-schaller.de/month/2008/02In RTF body
    • http://www.horland.de/cwsysinfo.htmlIn RTF body
    • http://www.joshcellsoftwares.com/In RTF body
    • http://www.opa-backup.de/In RTF body
    • http://www.componentsoftware.com/csdiff/In RTF body
    • http://www.winpooch.com/In RTF body
    • http://rpi.net.au/~ajohnson/resourcehackerIn RTF body
    • https://fspro.net/my-lockbox/In RTF body
    • http://www.ctmagazin.de/0916160In RTF body
    • http://www.schmidhorst.de/regdom}{In RTF body
    • http://www.it-techblog.de/vista-workshop-notebooks-drahtlos-ad-hoc-vernetzen/07/20In RTF body
    • http://www.ctmagazin.de/0In RTF body
    • http://forum.notebookreview.com/asus/150016-asus-notebook-keys-v1-3-a.htmlIn RTF body
    • http://forum.notebookreview.com/asus/150016-asus-notebook-In RTF body
    • http://forum.notebookreview.com/attachments/asus/12941d1196825791-asus-notebook-keys-v1-3-asusnbkeys_v1.3.zipIn RTF body
    • http://forum.notebookreview.com/attachments/asus/12942d1196825791-asus-notebook-keys-v1-3-asusnbkeys_v1.3_src.zipIn RTF body
    • http://www.ct.de/y3keIn RTF body
    • http://www.audiograbber.deIn RTF body
    • http://www.tmpgenc.netIn RTF body
    • http://www.cdex.n3.net/In RTF body
    • http://www.dbpoweramp.com/In RTF body
    • http://www.dbpoweraIn RTF body
    • http://www.s-a-d.deIn RTF body
    • http://www.germanixsoft.deIn RTF body
    • http://www.clipinc.deIn RTF body
    • http://www.arsgeek.com/?cat=20In RTF body
    • http://www.bihler-online.de/pascal/index.htmIn RTF body
    • http://www.bihler-online.de/pascal/index.hIn RTF body
    • http://www.ct.de/yfbqIn RTF body
    • http://pcwelt-tipps.de/wiki/Autostart_auf_USB-SticksIn RTF body
    • http://pcwelt-tipps.de/wiki/Autostart_auf_USB-SticIn RTF body
    • http://support.microsIn RTF body
    • http://www.basta.comIn RTF body
    • http://www.delphifreestuff.comIn RTF body
    • https://www.ct.de/yf71In RTF body
    • http://www.mlin.netIn RTF body
    • https://www.ct.de/yveaIn RTF body
    • http://www.SpywareInfo.comIn RTF body
    • http://dialerschutz.de/home/Loeschen/loeschen.htmlIn RTF body
    • https://www.ct.de/wimageIn RTF body
    +2217 more URL(s)

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00a0773b.bin rtf-objdata-decoded RTF \objdata at offset 0xA0773B 59544 bytes
SHA-256: 0555a6c226fb3f047e13d94709c57d8eac404669fa60c7f8719d995e9386bf43