Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 25ecb1a0385ebf1f…

MALICIOUS

RTF / .DOC

118.9 KB
MD5: 2692aa10af788c3874d5535820e467ae SHA-1: 2011ee11f89a0e13c2ed2cba9da495204d4c3e01 SHA-256: 25ecb1a0385ebf1f8020157fca78f7060c60275bb44482f4854462da3a96d50e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The file is an RTF document containing embedded OLE object data, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic suggests that this object is automatically activated upon opening, which is a common technique for exploiting vulnerabilities to download and execute further stages. The presence of OLE object data points towards a potential exploit delivery mechanism.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000044.bin
e3783e63914959cf2aa235177288c978447bd0f80def4d297270b77d2f58b156
rtf-objdata-decoded RTF \objdata at offset 0x44 38518 bytes