Malicious RTF — malware analysis report

Static analysis result for SHA-256 2ea7cb9bbd0fcad6…

MALICIOUS

RTF

171.7 KB First seen: 2024-06-27
MD5: 80e1ba7b421fd01f5319de00cf5420f7 SHA-1: d63b993303e677d7bacd6ab4a11b03530ee1528e SHA-256: 2ea7cb9bbd0fcad641bf6a0469f23c51786e1c0264b769a8ba0d5c5ff614b7ba
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The RTF file contains OLE object data and triggers automatic updates and activation, indicating it's designed to execute embedded content. The heuristics RTF_OBJDATA, RTF_OBJAUTLINK, and RTF_OBJUPDATE strongly suggest exploitation of OLE object vulnerabilities. While no specific payload or URL was directly extracted, the mechanism points towards a downloader or initial access vector.

Heuristics 3

  • Automatically linked OLE object high RTF_OBJAUTLINK
    RTF contains \objautlink — an automatically linked OLE object surface that can be updated or activated when Word opens the document.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000a65.bin
63aad59082042f8970282e66bcd11c73b508d421cfecc57046a1f00003c26808
rtf-objdata-decoded RTF \objdata at offset 0xA65 4187 bytes