Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 289dbd299dbf8627…

MALICIOUS

RTF / .DOC

8.7 KB
MD5: 2c4919ae42e2176d8959b774f8c8001d SHA-1: b92e89b69947d13e480b5780c3064d2179a14b9b SHA-256: 289dbd299dbf8627926da99d9e1553045be0c835ce4a748514bd53c8e25fe716
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The RTF document contains OLE object data and triggers an OLE activation event, indicating an attempt to exploit a vulnerability. The presence of embedded OLE object data suggests the document is designed to execute embedded code or trigger an exploit upon opening. While no specific script was extracted, the heuristics strongly suggest a malicious RTF exploit, likely leading to a secondary payload download.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001240.bin
3724be74b00baaf11464164dac9234b47ddab03d40b8cdb86f4d09e0e4d66927
rtf-objdata-decoded RTF \objdata at offset 0x1240 1320 bytes