Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 2862f356e09499e2…

MALICIOUS

RTF / .DOC

217.2 KB
MD5: bfa39f3e5b955bea79b87576e47ae465 SHA-1: 2a473b7f994bc8831af87e18ab1f6f1ff110d346 SHA-256: 2862f356e09499e2c2e9bb24a7ac902a4912236d12a3c89ac5b7f0e2400f353e
60 Risk Score

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000014b5.bin
59fc5602ac0a4b4546e4647984fea3c77a8866af777e8120e9a44c212f33a4a3
rtf-objdata-decoded RTF \objdata at offset 0x14B5 3661 bytes