Malicious RTF — malware analysis report

Static analysis result for SHA-256 e338747a4f62d182…

MALICIOUS

RTF

665.3 KB Created: 2017-10-30 10:54:00 First seen: 2021-02-23
MD5: c4c9a248d294c5d98a5d6cf28ab57641 SHA-1: 526c0538e64c77b6407f2b86762e3c095cd0054f SHA-256: e338747a4f62d1826ee92cf74ae3161bb817a19eefec7902f4f334c43bf94399
202 Risk Score

Heuristics 5

  • ClamAV: Doc.Macro.Obfuscation-6391394-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Macro.Obfuscation-6391394-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002a88.bin rtf-objdata-decoded RTF \objdata at offset 0x2A88 20545 bytes
SHA-256: cca9f160afa26b2a5e99bd5cf2ab6722da0afe2a08e77cca27dad9e8082057f5
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_01_off0001248f.bin rtf-objdata-decoded RTF \objdata at offset 0x1248F 20545 bytes
SHA-256: b2b054ec37f56f833d693c9ef4f6f1f71f67dce59b4b8a57309733f24a74209f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_02_off00021e98.bin rtf-objdata-decoded RTF \objdata at offset 0x21E98 20545 bytes
SHA-256: d64eaf50bd3ad19a36ba622651e38b646f80b28ac9a1b7543bb21a4e24153618
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_03_off000318a1.bin rtf-objdata-decoded RTF \objdata at offset 0x318A1 20545 bytes
SHA-256: fa081f24291a06feb3c40b11ca68740f8d70363157b825050d463e36090c2c14
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_04_off000412aa.bin rtf-objdata-decoded RTF \objdata at offset 0x412AA 20545 bytes
SHA-256: 9297dc4b9dcebb1adb1439c307f128309fb07f44b0a881e4db16f4bfe283209e
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_05_off00050cb3.bin rtf-objdata-decoded RTF \objdata at offset 0x50CB3 20545 bytes
SHA-256: db9a8de1fd08a9095c6ebcb1c2433443eebbba426fff6e92f4a35c932069d4e6
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_06_off000606bc.bin rtf-objdata-decoded RTF \objdata at offset 0x606BC 20545 bytes
SHA-256: 09f7f183f658608ac955136842ad439ca0293b89de6351e3f513adf3af6078fa
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_07_off000700c5.bin rtf-objdata-decoded RTF \objdata at offset 0x700C5 20545 bytes
SHA-256: 5e80d092a9d3d737a6ed0b0c7db677411a24f68f8a62003a9f694aae5b6054cc
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_08_off0007face.bin rtf-objdata-decoded RTF \objdata at offset 0x7FACE 20545 bytes
SHA-256: edb4cb5ca67e8ed0639d1227b69bafb55b5bddc6707e7e554d93f814922a0e5a
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely
objdata_09_off0008f4d7.bin rtf-objdata-decoded RTF \objdata at offset 0x8F4D7 20545 bytes
SHA-256: a3912dd4d306d042b500674306ed5390160e29c629f07b34371c65662b26837f
Detection
ClamAV: Doc.Macro.Obfuscation-6391394-0
Obfuscation or payload: unlikely