Malicious RTF — malware analysis report

Static analysis result for SHA-256 349f26c6779919a0…

MALICIOUS

RTF

3.0 KB First seen: 2022-11-23
MD5: 0607f8cb8a8775d3b564f7481a391272 SHA-1: 579d74528dddcd11133f8622fa748a08211b1bc8 SHA-256: 349f26c6779919a00267baa7503f4451d613b27163a144755ec0ece693e15ab3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains embedded OLE object data and uses an \objupdate directive, indicating an attempt to exploit vulnerabilities related to OLE object activation. This suggests a malicious document designed to leverage embedded objects for arbitrary code execution upon opening. No specific family is identifiable from the provided heuristics.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000076.bin
9a9d0d881e80601c612b8b16783e2c3b4f50e3c6e5f6a2c119958f696e6a5218
rtf-objdata-decoded RTF \objdata at offset 0x76 1449 bytes