MALICIOUS
842
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1059.007 Command and Scripting Interpreter: JavaScript
T1190 Exploit Public-Facing Application
This RTF document exploits CVE-2023-21716 via an anomalous font table to achieve code execution. It contains a PHP webshell and references to tools like cmd.exe, certutil, bitsadmin, and PowerShell, indicating a likely intent to download and execute further payloads or establish remote code execution. The document body also contains lures for remote support and phone scams, suggesting a multi-stage attack.
Heuristics 23
-
CVE-2023-21716 — \fonttbl with 32768 entries critical CVE exact CVE_2023_21716RTF font table contains 32768 font entries, which is highly anomalous — CVE-2023-21716 triggers a heap buffer overflow in Word's RTF font table parser when the number of entries is very large (exploitable from ~32768 entries). This document is suspicious.
-
URL Moniker in RTF OLE object high RTF_URL_MONIKER_RELATEDRTF contains a URL Moniker GUID in OLE object context, but no decoded remote target was confirmed. Treat as related OLE2Link attack-surface evidence rather than proof of CVE-2017-0199 exploitation.
-
PHP webshell / backdoor source critical WEBSHELL_PHPThe file contains PHP server-side code with the signature of a webshell/backdoor (request input fed to a command/code-exec sink with a decoder/second sink (RCE backdoor)). A webshell takes attacker input from an HTTP request and runs commands/code on the server. Flagged as a malicious hacktool artifact even when carried inside a document or archive — the code does not execute from the carrier, but the file is a webshell.
-
Reference to WinExec API high SC_STR_WINEXECReference to WinExec API
-
Reference to CreateProcess API high SC_STR_CREATEPROCESSReference to CreateProcess API
-
Reference to ShellExecute API high SC_STR_SHELLEXECReference to ShellExecute API
-
Suspicious cmd.exe invocation with execution flag high SC_STR_CMDSuspicious cmd.exe invocation with execution flag
-
Reference to PowerShell high SC_STR_POWERSHELLReference to PowerShell
-
Reference to Windows Script Host high SC_STR_WSCRIPTReference to Windows Script Host
-
Reference to certutil (download/decode) high SC_STR_CERTUTILReference to certutil (download/decode)
-
Reference to bitsadmin (download) high SC_STR_BITSADMINReference to bitsadmin (download)
-
Reference to LoadLibrary API high SC_STR_LOADLIBRARYReference to LoadLibrary API
-
Reference to GetProcAddress API high SC_STR_GETPROCADDRESSReference to GetProcAddress API
-
Large hex data blocks in OLE object high RTF_EXCESSIVE_HEXRTF contains ~1167KB of hex-encoded data inside \objdata sections — may hide a payload
-
Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LUREDocument tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Remote-support tool lure high SE_REMOTE_SUPPORT_LUREDocument instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
-
Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
x86 push-string-call medium SC_PUSH_STRINGShellcode-style PUSH imm32 sequence builds an execution, network, or Windows API string on the stackDisassembly hidden — these bytes score as data, not coherent x86 code (3/9 branch targets land on an instruction boundary (33% coherence)).
-
OLE object data medium RTF_OBJDATARTF contains 1 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAMRTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.schmidhorst.de/regdom In RTF body
- http://www.delphipraxis.net/118485-ermitteln-ob-32-bit-oder-64-bit-betriebssystem.htmlIn RTF body
- http://www.ebay.com:verify@www.spion.comIn RTF body
- http://www.windowspro.de/tipp/einfaches-single-sign-workgroups-und-mit-samba-durch-cmdkeyIn RTF body
- http://www.computer-engineering.orgIn RTF body
- http://www.softwareok.de/?Microsoft/DontSleepIn RTF body
- https://www.opautoclicker.com/In RTF body
- http://www.tnk-bootblock.co.uk/prods/miscIn RTF body
- http://www.docu-track.com/home/prod_user/PDF-XChange_Tools/pdfx_viewer/In RTF body
- http://www.it-techblog.de/vista-workshop-notebooks-drahtlos-ad-hoc-vernetzen/07/2007/In RTF body
- http://jens-schaller.de/month/2008/02In RTF body
- http://www.horland.de/cwsysinfo.htmlIn RTF body
- http://www.joshcellsoftwares.com/In RTF body
- http://www.opa-backup.de/In RTF body
- http://www.componentsoftware.com/csdiff/In RTF body
- http://www.winpooch.com/In RTF body
- http://rpi.net.au/~ajohnson/resourcehackerIn RTF body
- https://fspro.net/my-lockbox/In RTF body
- http://www.ctmagazin.de/0916160In RTF body
- http://www.schmidhorst.de/regdom}{In RTF body
- http://www.it-techblog.de/vista-workshop-notebooks-drahtlos-ad-hoc-vernetzen/07/20In RTF body
- http://www.ctmagazin.de/0In RTF body
- http://forum.notebookreview.com/asus/150016-asus-notebook-keys-v1-3-a.htmlIn RTF body
- http://forum.notebookreview.com/asus/150016-asus-notebook-In RTF body
- http://forum.notebookreview.com/attachments/asus/12941d1196825791-asus-notebook-keys-v1-3-asusnbkeys_v1.3.zipIn RTF body
- http://forum.notebookreview.com/attachments/asus/12942d1196825791-asus-notebook-keys-v1-3-asusnbkeys_v1.3_src.zipIn RTF body
- http://www.ct.de/y3keIn RTF body
- http://www.audiograbber.deIn RTF body
- http://www.tmpgenc.netIn RTF body
- http://www.cdex.n3.net/In RTF body
- http://www.dbpoweramp.com/In RTF body
- http://www.dbpoweraIn RTF body
- http://www.s-a-d.deIn RTF body
- http://www.germanixsoft.deIn RTF body
- http://www.clipinc.deIn RTF body
- http://www.arsgeek.com/?cat=20In RTF body
- http://www.bihler-online.de/pascal/index.htmIn RTF body
- http://www.bihler-online.de/pascal/index.hIn RTF body
- http://www.ct.de/yfbqIn RTF body
- http://pcwelt-tipps.de/wiki/Autostart_auf_USB-SticksIn RTF body
- http://pcwelt-tipps.de/wiki/Autostart_auf_USB-SticIn RTF body
- http://support.microsIn RTF body
- http://www.basta.comIn RTF body
- http://www.delphifreestuff.comIn RTF body
- https://www.ct.de/yf71In RTF body
- http://www.mlin.netIn RTF body
- https://www.ct.de/yveaIn RTF body
- http://www.SpywareInfo.comIn RTF body
- http://dialerschutz.de/home/Loeschen/loeschen.htmlIn RTF body
- https://www.ct.de/wimageIn RTF body
+2217 more URL(s)
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off00a0773b.bin |
rtf-objdata-decoded | RTF \objdata at offset 0xA0773B | 59544 bytes |
SHA-256: 0555a6c226fb3f047e13d94709c57d8eac404669fa60c7f8719d995e9386bf43 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.