Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 22c6cb28e8da3b71…

MALICIOUS

RTF / .DOC

11.0 KB
MD5: b69f10b44dfc89ed9f3c4cce4329e470 SHA-1: 0ddf069cd3b18aeb88cf246d4bd18be2af6e68f4 SHA-256: 22c6cb28e8da3b71d9c3d14f2c1fb8f2b5905fd83a2b8b0b5e5089d336e93ba2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains embedded OLE object data and uses \objupdate to force activation, indicating an attempt to exploit a vulnerability. The heuristics suggest this is likely an attempt to deliver a malicious payload, possibly through a macro or embedded exploit. No document body or script content was available for further analysis, limiting the ability to determine the exact payload or family.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001b88.bin
5bde57c5bbf4886a6f12c825ee150bdcb66d7c036c98ce7af9145c36f6a99a6f
rtf-objdata-decoded RTF \objdata at offset 0x1B88 1502 bytes