Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 0c10532495658ae6…

MALICIOUS

RTF / .DOC

600.4 KB
MD5: 62d9f219d4c67d21a6a125597804821b SHA-1: 48a46d13ff5571ba085cbd4b9f6575a400199d24 SHA-256: 0c10532495658ae6099011796249e76b9ef33235a019df54086bd07547685354
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF document contains heuristics indicating the presence of automatically linked and updating OLE objects, a common method for embedding malicious content. The document body explicitly instructs the user to 'Enable editing', suggesting a lure to bypass security measures. This combination strongly suggests the file is designed to exploit OLE object activation to download and execute a secondary payload.

Heuristics 4

  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00039af7.bin
7e2ff8d90d1c9f69ed184f488688dbce36cfbb75a148c7dc8ccc29346c7f263c
rtf-objdata-decoded RTF \objdata at offset 0x39AF7 1610 bytes