Malicious RTF — malware analysis report

Static analysis result for SHA-256 049e85bb9fdc0bbc…

MALICIOUS

RTF

66.6 KB First seen: 2025-08-13
MD5: 3f22b0cd1edff35c28d6deeec3dec2b0 SHA-1: 329afd6f3f98f18b8d7d4b06c0c78a7e829897e2 SHA-256: 049e85bb9fdc0bbc9dfd342897475c02d17e602d7b270edf30f01ba43a879207
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains embedded OLE object data and uses an \objupdate directive, indicating an attempt to automatically activate these objects. This is a common technique for delivering malicious payloads. Since no document body or script content was available for analysis, the specific payload or delivery mechanism cannot be determined.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000f5a.bin
4a535bdc0a5ec4969fb1b58554094847b4b54470a9850a8d22f152b765ac8432
rtf-objdata-decoded RTF \objdata at offset 0xF5A 3734 bytes