MALICIOUS
102
Risk Score
Heuristics 4
-
ClamAV: Doc.Exploit.DDEautoexec-6346603-1 critical CLAMAV_DETECTIONClamAV detected this file as malware: Doc.Exploit.DDEautoexec-6346603-1
-
OLE object data medium RTF_OBJDATARTF contains 10 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off000035b0.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x35B0 | 19505 bytes |
SHA-256: b3aeb1d6c2aa65e8c09acc2c964c144096a4187260de056c606f147eafbc5488 |
|||
objdata_04_off00030a28.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x30A28 | 19505 bytes |
SHA-256: 172b8dadaba400f09852cca3464022d18dbf4ebf2f1572ec73da68c0ac2069c5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.