Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 3c9280552a4129fd…

MALICIOUS

RTF / .DOC

21.1 KB
MD5: 17ca06000e92058f0d43259b2683537c SHA-1: db453e5125310d209fe04fb0211677d79d25f3ee SHA-256: 3c9280552a4129fdf884414b080c80d5ffc72403079d7a5292e9b09d832ab37d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains OLE object data and uses \objupdate to force OLE activation, indicating an attempt to exploit a vulnerability. The high-severity heuristic for \objupdate suggests a malicious intent to execute embedded content. Without a document body or scripts, the exact payload and delivery mechanism remain unclear, but the OLE object activation is the primary indicator of compromise.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001f1a.bin
d94db0bb33feb67c2e1dacdc9343ee7c6bf153d62c04f2c02b3d4905cdba6b3b
rtf-objdata-decoded RTF \objdata at offset 0x1F1A 1682 bytes