Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 05d22388ec7af8d1…

MALICIOUS

RTF / .DOC

3.6 KB First seen: 2022-10-22
MD5: 110b4e92b90088de3fe2b6f7b8f0b685 SHA-1: 2da134f68c1917622f557a6a68238ad523794a8e SHA-256: 05d22388ec7af8d1bc1d11892d65682c958fe3fc114d2da827ff0caa3d4a8086
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains an OLE object with ".objupdate" directive, indicating an attempt to trigger OLE activation and exploit a vulnerability. This is a common technique for delivering malicious payloads. The specific exploit targeted is not identifiable from the provided heuristics.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000074.bin
f75aae3b7df8383da0b6d308967b44cc2e418d9b188f59b89ece5af84fd7d181
rtf-objdata-decoded RTF \objdata at offset 0x74 1709 bytes