Malicious RTF — malware analysis report

Static analysis result for SHA-256 04258bdfb2e229da…

MALICIOUS

RTF

20.3 KB Authoring application: Msftedit 5.41.21.2510 First seen: 2019-05-16
MD5: 60698627235668115fd6485255578a01 SHA-1: 7935f81dbfdbcb57de28ba11c87073d9c1221165 SHA-256: 04258bdfb2e229da241d9d598a8ad0195f045485467abd1c7abaad30c4ed11d2
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains an embedded OLE object, identified as a package object. The document body provides a simple instruction to click the field, suggesting a lure to execute the embedded object. The embedded object is likely a malicious payload, leading to exploitation for client execution.

Heuristics 3

  • Package object class high RTF_OBJCLASS_PACKAGE
    OLE Package object — can wrap arbitrary files
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000239b.bin rtf-objdata-decoded RTF \objdata at offset 0x239B 1665 bytes
SHA-256: 8c88a72175443ef2b172300daac5db3ebefc331804041b3fa0b2a789200d9089