Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 f4e18a5f9b49a86a…

MALICIOUS

RTF / .DOC

1.6 KB
MD5: 71952314ad325054bb34a946967598c9 SHA-1: 3fbb31a74938f15a805cf41dbe1f4159ad0f63f4 SHA-256: f4e18a5f9b49a86a0095eaa6a5abeb2227f28392854fe558fa154817b11a81c2
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The RTF document contains a remote template injection heuristic pointing to a suspicious URL, indicating an attempt to download additional content. The document body, written in Traditional Chinese, frames the malicious act as a social engineering exercise, instructing the user on how to avoid such attacks, which is a common lure tactic. The embedded URL is the primary indicator of a potential second-stage payload delivery.

Heuristics 2

  • Remote template injection (\*\template → remote URL) critical CVE related RTF_REMOTE_TEMPLATE
    The RTF's \*\template destination is a remote URL/UNC path. When Word opens the document it fetches and loads that template, which can carry macros or an exploit, deliver a scriptlet/HTA, or leak NTLM credentials over UNC. Benign documents attach only a local template, so a remote \*\template target is template-injection delivery (MITRE T1221). remote \*\template target (Word fetches it on open); dynamic-DNS / abuse-prone host; target is active/script content, not a .dot template.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://solmo.twilightparadox.com/2ce69c650391534c76686e17f50b39ae0ec268a7/0098401040350.html