MALICIOUS
102
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The RTF file contains OLE object data and triggers a high-severity heuristic for CVE-2012-0158, indicating exploitation of a vulnerability in MSCOMCTL.ListView. This suggests the file is designed to execute arbitrary code upon opening, likely delivered via spearphishing. No specific family could be identified.
Heuristics 4
-
MSCOMCTL.ListView — CVE-2012-0158 high CVE_2012_0158RTF \objdata decodes to OLE data containing the MSCOMCTL.ListView — CVE-2012-0158 CLSID — the vulnerable control/moniker is embedded directly in the document's object stream, the delivery shape of this exploit. RTF objects auto-render when Word opens the file.
-
Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
OLE object data medium RTF_OBJDATARTF contains 5 \objdata section(s) — embedded OLE objects
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off0003bff9.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x3BFF9 | 440 bytes |
SHA-256: ea5d234f81e7c6f4d2681a1e14ba35656c4caea1ff0358220f369a5f5b5ba6da |
|||
objdata_01_off0003c3e1.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x3C3E1 | 8894 bytes |
SHA-256: 7e65564a9a0b8615fbfea6ef11c41fbcc14b2abc7be0c991457751a7098fb653 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Static shellcode analysis recovered command string(s): cmd.exe /c reg delete "HKCU\Software\Microsoft\Office\11.0\Word\Resiliency" /F
|
|||
objdata_02_off0003e775.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x3E775 | 2361 bytes |
SHA-256: 01b5c1107f9bf512b7dbea22d48eef58e0f38766928ea70c2461238f8566efc7 |
|||
objdata_03_off00045f41.bin |
rtf-objdata-decoded | RTF \objdata at offset 0x45F41 | 108925 bytes |
SHA-256: bd98489459536335ffd265f832d1fa9a8beafd5aaec5bf298c121e3cb2bb6c78 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.