Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 26c09e11e1095a19…

MALICIOUS

RTF / .DOC

291.7 KB
MD5: f25eb8dcf7ea601039adb40733385578 SHA-1: 64f1d06320641f68c29563b479dec38622201666 SHA-256: 26c09e11e1095a1905a5e68fad4e91bb1594b4d43291ee750f4aa442f427d28b
160 Risk Score

Malware Insights

MITRE ATT&CK
T1559.001 Component Object Model Hijacking T1137.001 DLL Search Order Hijacking

The RTF document contains multiple OLE objects, with high-confidence heuristics indicating automatic linking and update mechanisms that trigger OLE activation. This suggests the document is designed to exploit these OLE features to execute embedded malicious code. No specific family could be identified, and no external IOCs were extracted.

Heuristics 5

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 4 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000007f8.bin
3abd0500d05b8f8f8956c8b3816a4b411a9cb49dbe6888008a59dbb5d1a42c7e
rtf-objdata-decoded RTF \objdata at offset 0x7F8 44551 bytes
objdata_01_off00004106.bin
89fa6e00483ff7fbe9ffd427bc50f32fc40ac260acf8731d6f2f4b4b0b6fbcd3
rtf-objdata-decoded RTF \objdata at offset 0x4106 44525 bytes
objdata_02_off0001ab6b.bin
9898055bd0f8f4ea4768ba3581db647387d886eacf12252bf69adb6e4fce9c36
rtf-objdata-decoded RTF \objdata at offset 0x1AB6B 2632 bytes
objdata_03_off0001c10e.bin
e8d4fe950caed6dcfde26f4b616825bbe11b93458425974b7d075167f675abf7
rtf-objdata-decoded RTF \objdata at offset 0x1C10E 12297 bytes