Malicious RTF — malware analysis report

Static analysis result for SHA-256 3fcd797192ecab39…

MALICIOUS

RTF

8.3 KB
MD5: 91838b9d14e012553a323ca4e9261547 SHA-1: 5281d1d2317c3721f4a0dc7942ff79524efbe885 SHA-256: 3fcd797192ecab39c41ba35aa62682d177aa0b8d355065bcd13e9a150a3098fb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious File

The file is an RTF document containing OLE object data, which is activated by an \objupdate directive. This suggests the document is designed to exploit OLE vulnerabilities or embed malicious objects. While no specific document body content or scripts were extracted, the presence of OLE object data and the \objupdate heuristic strongly indicate a malicious intent to execute embedded code or trigger an exploit upon opening.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000cb1.bin
af1427b0742a3bccb9f1815aeb7aeb8553d2a0f34f63633e514b538ba52231b8
rtf-objdata-decoded RTF \objdata at offset 0xCB1 1896 bytes