Win.Trojan.FormBook-6749867-0 — RTF malware analysis

Static analysis result for SHA-256 d9f1d308addfdeba…

MALICIOUS

RTF

397.4 KB First seen: 2019-05-16
MD5: 775791d635235a462d38ab6b34bdbf1b SHA-1: 44e9d1fb32b90c069573a248296c6d8d79734a8b SHA-256: d9f1d308addfdebaa7183ca180019075c04cd51a96b1693a4ebf6ce98aadf678
120 Risk Score

Malware Insights

Win.Trojan.FormBook-6749867-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains OLE object data and uses \objupdate to force activation, indicating an attempt to exploit a vulnerability. ClamAV identifies the sample as Win.Trojan.FormBook-6749867-0, a known information-stealing malware. The presence of embedded OLE objects strongly suggests exploitation for client execution, likely delivered via spearphishing.

Heuristics 3

  • ClamAV: Win.Trojan.FormBook-6749867-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.FormBook-6749867-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000003c.bin rtf-objdata-decoded RTF \objdata at offset 0x3C 82009 bytes
SHA-256: 6aa2992d489c86caa343c4073a8af50ccc824c42fa7cdc57e992e88bc766b5ec