Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 28d3686e000cdecf…

MALICIOUS

RTF / .DOC

3.7 KB First seen: 2022-11-28
MD5: 8572bfd9fafac60258715f51531cf12c SHA-1: 660344d8ad0243e404e2796523c0b876d4c16c16 SHA-256: 28d3686e000cdecf5d775263e5e33bfa7c23bee782e58b1cb7dd7bdb952b5964
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains OLE object data and an \objupdate directive, indicating an attempt to exploit a vulnerability when the object is activated. This is a common technique for delivering malicious payloads.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000007e.bin
92b525c44c2ab6d6299bf8a3157c502bfa0b356fb4eaf6f66bb4ade7b42e200b
rtf-objdata-decoded RTF \objdata at offset 0x7E 1777 bytes