Malicious RTF — malware analysis report

Static analysis result for SHA-256 1f9ff969479ae43d…

MALICIOUS

RTF

108.1 KB
MD5: 9dc1cdba6d5838f7984de89521f18ae8 SHA-1: 80d00bcd9ab9be3054ebfa20eb22cef9aadfcc49 SHA-256: 1f9ff969479ae43d47a109712d05a084490c1d7ad38aa50bef2b1cd20f5037be
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains multiple OLE objects, with heuristics indicating that \objupdate forces OLE activation and composite monikers are related to the OLE object. This suggests the file is designed to exploit these OLE features to execute embedded code. The SHA256 hash is included as a primary identifier for this malicious file.

Heuristics 4

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 4 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000095.bin
01a58888af6456e05f9287ee6d1a71085a4a39829729e5e4623cb17c861aef7f
rtf-objdata-decoded RTF \objdata at offset 0x95 33042 bytes
objdata_01_off000102ff.bin
d39476b572775e2d2ccff7067a93b83262e504692939d91f0a91f08d6c32912a
rtf-objdata-decoded RTF \objdata at offset 0x102FF 186 bytes
objdata_02_off000104b9.bin
526ac0cda7ec1f931e1dc48768480a9f035896d7c9169d7db4f1eb87294753ce
rtf-objdata-decoded RTF \objdata at offset 0x104B9 19303 bytes
objdata_03_off00019bb6.bin
00c96c842c8b4c19494c5d27881c889eee8fd539a350c7e16121a8fc412837c0
rtf-objdata-decoded RTF \objdata at offset 0x19BB6 2633 bytes