Malicious RTF — malware analysis report

Static analysis result for SHA-256 d397801417629197…

MALICIOUS

RTF

943.0 KB Created: 2018-06-08 08:31:00 First seen: 2021-02-23
MD5: fe8af729af3d5428d6268a0628cd251f SHA-1: 6e124373039cdc2a1f95d223545b6825276f07fe SHA-256: d3978014176291973f9f2031f57f4dcee736d206a1c48b1e64f347b72005ce78
262 Risk Score

Heuristics 7

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Generic-6834349-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Generic-6834349-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003b92.bin rtf-objdata-decoded RTF \objdata at offset 0x3B92 34875 bytes
SHA-256: 1960d82bfd1d9a783af96623f45680b4ccb7850ce7696748dd43847afe8e3a47
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_01_off0001a4be.bin rtf-objdata-decoded RTF \objdata at offset 0x1A4BE 34875 bytes
SHA-256: 6e33e0f3e4ba38322983cdc6e049ea2f3b3548a94438bc665de6ce8d389e4df8
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_02_off00030dea.bin rtf-objdata-decoded RTF \objdata at offset 0x30DEA 34875 bytes
SHA-256: 2069e0b52fcec575f8af8a9396e503b10924cb60b38044941ca91109f47a0e25
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_03_off00047716.bin rtf-objdata-decoded RTF \objdata at offset 0x47716 34875 bytes
SHA-256: bbe5d656463d04956aae2da5b573bce5cd71f1e5562ccd7d0b4d498cbd56f2bf
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_04_off0005e042.bin rtf-objdata-decoded RTF \objdata at offset 0x5E042 34875 bytes
SHA-256: d7c236d472dcada6ec426d604630205b0921b52acf60ec5ba93ac701a0c57eaa
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_05_off00075097.bin rtf-objdata-decoded RTF \objdata at offset 0x75097 34875 bytes
SHA-256: 1532a035f9b93caf46e9444a5754f17551f9cd0898860e643085af0dbef02983
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_06_off0008b9c0.bin rtf-objdata-decoded RTF \objdata at offset 0x8B9C0 34875 bytes
SHA-256: 22e88fc6849d707ad65c9463eef64660a898134b88db2244eb03f007ca468195
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_07_off000a22e9.bin rtf-objdata-decoded RTF \objdata at offset 0xA22E9 34875 bytes
SHA-256: dfd3525c4f178d751bd27518bc0d74a8942eb28a604697800415b20fd8cf10f0
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_08_off000b8c12.bin rtf-objdata-decoded RTF \objdata at offset 0xB8C12 34875 bytes
SHA-256: b8c436b2c08b9e20f2ca904875d5f8b4923eb799e2d7579c36e36a17db0e079c
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely
objdata_09_off000cf53b.bin rtf-objdata-decoded RTF \objdata at offset 0xCF53B 34875 bytes
SHA-256: cf62fb72bc41fed50a9e1ce87da22c33e7635713d00f92051f584df2cf5631b7
Detection
ClamAV: Xls.Malware.Generic-6834349-0
Obfuscation or payload: unlikely