Malicious RTF — malware analysis report

Static analysis result for SHA-256 219075682d10748a…

MALICIOUS

RTF

229.3 KB Created: 2019-12-08 22:24:00
MD5: c2f5acb4dbb10cbae38a108ea7cbfe9f SHA-1: bc7598c239b1afb572c945b4d52a417403efc8e2 SHA-256: 219075682d10748a701b56a5862b73273ff2d089410cede70215488d4492bbe6
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains multiple OLE objects, with one specifically triggering an objupdate directive. This suggests an attempt to exploit vulnerabilities or execute embedded code upon opening. While the specific payload or exploit is not directly evident from the static analysis, the presence of these OLE objects strongly indicates a malicious intent, likely for initial access.

Heuristics 4

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 3 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000087f7.bin
38af583621f0e25f776571c9c80be877b498014423d04e7d5f7300b14d542ccc
rtf-objdata-decoded RTF \objdata at offset 0x87F7 15892 bytes