Malicious RTF — malware analysis report

Static analysis result for SHA-256 f58a78f010d0c733…

MALICIOUS

RTF

1.76 MB Created: 2004-09-13 20:02:00
MD5: e89022e4bd90c254259f8baf24b4fc1b SHA-1: e7c787cf1deb640f6aa0c21518d61431b9d31d90 SHA-256: f58a78f010d0c733bdfdc7fb405cc6a96e3cfa395fc1661ae5b133850aa2715f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains significant amounts of hex-encoded data within an OLE object, a common technique for hiding malicious payloads. The presence of a Composite Moniker further suggests an attempt to exploit OLE object handling. While the document body presents a benign registration form, the heuristics strongly indicate the RTF structure itself is designed to deliver an embedded exploit or payload. No scripts were extracted, and the only URL found was benign.

Heuristics 5

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • Large hex data blocks in OLE object high RTF_EXCESSIVE_HEX
    RTF contains ~1813KB of hex-encoded data inside \objdata sections — may hide a payload
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml}}\paperw12240\paperh15840\margl1440\margr1440\margt1440\margb1440\gutter0\ltrsect

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001de6.bin
d6d548100ab31a0bb3141318ac9be0f97d78a126170abcf689293c2d2a387d1a
rtf-objdata-decoded RTF \objdata at offset 0x1DE6 187332 bytes