Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 019d507bcc3ca85c…

MALICIOUS

RTF / .DOC

594.6 KB Authoring application: Msftedit 5.41.15.1507
MD5: 41e080b6f66f9bf0b9a29f119fced8ff SHA-1: 6515d48ada629bf9f145829cb7f044e7f4578051 SHA-256: 019d507bcc3ca85c46cc5855c84b3261898e39286e9e737f3429a265a69be676
140 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1204.002 Malicious File

The RTF file contains embedded OLE objects, one of which has a PE header. This strongly suggests the document is a dropper for an executable payload. The presence of RTF-specific heuristics like RTF_OBJDATA, RTF_OBJEMB, and RTF_OBJCLASS_PACKAGE further supports this, pointing to the malicious nature of the embedded object.

Heuristics 4

  • PE header (with DOS stub) in hex data critical RTF_MZ_HEX
    Hex-encoded PE (MZ + DOS stub) found inside RTF — likely an embedded executable payload
  • Package object class high RTF_OBJCLASS_PACKAGE
    OLE Package object — can wrap arbitrary files
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000d1.bin
eee4ce595d1c6bcdb6d7a21de3af265252ebbd359db1c29f15f1f4cb0eb9b32b
rtf-objdata-decoded RTF \objdata at offset 0xD1 292984 bytes