Malicious RTF — malware analysis report

Static analysis result for SHA-256 4c2b4d24f9ca48c0…

MALICIOUS

RTF

931.4 KB Created: 2019-07-01 21:08:00 First seen: 2021-04-25
MD5: 424b42a450ace0281e45f04b0622ef22 SHA-1: bc0238beb7cb79e2c15db180d2074583f3c88124 SHA-256: 4c2b4d24f9ca48c0e51ab9f33c2d488f373bb5ff8cddb2a85a08c1bfe873730f
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF document contains multiple OLE objects, with heuristics indicating that \objupdate forces OLE activation. This suggests the file is designed to exploit OLE object handling to execute embedded content, likely leading to a second-stage payload. No specific family could be identified from the available evidence.

Heuristics 5

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 15 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • OlePres presentation stream in RTF OLE object medium RTF_OLEPRES_STREAM
    RTF contains an embedded OLE object with an OlePres presentation stream. OlePres is an OLE presentation marker and is not enough on its own to identify CVE-2025-21298.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002c9b.bin rtf-objdata-decoded RTF \objdata at offset 0x2C9B 19003 bytes
SHA-256: 3524185bca81b1027a57d7f63eee6e412b5a6fe9ac2dcef1144caf449b21a706
objdata_01_off00011ab9.bin rtf-objdata-decoded RTF \objdata at offset 0x11AB9 19003 bytes
SHA-256: f8cb12be836f8cd9fac21faf100c8653cb5848023d408f9f72a5e86635c78192
objdata_02_off000208d7.bin rtf-objdata-decoded RTF \objdata at offset 0x208D7 19003 bytes
SHA-256: 3d85ac6d60fdd5f7ec2c788606d75eaca261319e5dfc8cd77b4cb4f6cd7ae4cc
objdata_03_off0002f6f5.bin rtf-objdata-decoded RTF \objdata at offset 0x2F6F5 19003 bytes
SHA-256: c0b22515973fd597edfbecc6e7663a747aa7356353fcc191e9f8c2c001615e7e
objdata_04_off0003e513.bin rtf-objdata-decoded RTF \objdata at offset 0x3E513 19003 bytes
SHA-256: 5760648d457fcd31003347e8d449fef1bec0ab2ce70a4c40064aaadcbeb78651
objdata_05_off0004d331.bin rtf-objdata-decoded RTF \objdata at offset 0x4D331 19003 bytes
SHA-256: 443e2ccf80079bb718d97465ce388bc724eadec9e82272e9ed9d9d809ebfe708
objdata_06_off0005c14f.bin rtf-objdata-decoded RTF \objdata at offset 0x5C14F 19003 bytes
SHA-256: c5dffbfd25f48b862fd3ab73e85889dae36625bf469a4431e43befe1d1f70a90
objdata_07_off0006af6d.bin rtf-objdata-decoded RTF \objdata at offset 0x6AF6D 19003 bytes
SHA-256: 54778ccf5cdab9a326d651ee32285e202ff8561c95203a7da49108f62eb1a38f
objdata_08_off00079d8b.bin rtf-objdata-decoded RTF \objdata at offset 0x79D8B 19003 bytes
SHA-256: 82d548f6d6fda9ed021ae88ee58f356717054b169d70ee49b18f218bd785a489
objdata_09_off00088ba9.bin rtf-objdata-decoded RTF \objdata at offset 0x88BA9 19003 bytes
SHA-256: 64106386be40c35689e3b3da14457125f5444f510a119ffe15a4915464740e46
objdata_10_off000979c7.bin rtf-objdata-decoded RTF \objdata at offset 0x979C7 19003 bytes
SHA-256: 807141b2fc41593816fb17d3f8a691d070f1e4024b3a151572b781ea32f24668
objdata_11_off000a67e5.bin rtf-objdata-decoded RTF \objdata at offset 0xA67E5 19003 bytes
SHA-256: 10238036fc2a19bb2b2da23bf7fcd6070008355e5b55f41285e3bcec7e81fabc
objdata_12_off000b5603.bin rtf-objdata-decoded RTF \objdata at offset 0xB5603 19003 bytes
SHA-256: 922f3eb49a75bf23c998128a449a6fe814866a0ef3618a2ea497dda1184c4abb
objdata_13_off000c4421.bin rtf-objdata-decoded RTF \objdata at offset 0xC4421 19003 bytes
SHA-256: f88c811c7195f4a105a4a170ef00d4dc3bf9bbd8fac7d3aa6f7fc4e55b42916f
objdata_14_off000d323f.bin rtf-objdata-decoded RTF \objdata at offset 0xD323F 19003 bytes
SHA-256: 58a6306c42bb4b8cfb9e228c9efcad69a636b029ed0c2dec1c285cc582b2a4e6