Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 4f12ba7491332dd8…

MALICIOUS

RTF / .DOC

22.0 KB
MD5: ad1d6c86f6ff337b67ed55734331c808 SHA-1: 8bfc8746f3e000e0bf3c126ee84dd5b50d7011c6 SHA-256: 4f12ba7491332dd8cfde38562a3e26ba74c5c4e9b5754232cd4ed98071749d70
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains embedded OLE object data and triggers an \objupdate event, indicating an attempt to exploit a vulnerability. This suggests the document is designed to execute malicious code upon opening. The specific exploit and payload are not discernible from the provided heuristics and truncated document body.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001e50.bin
f8ad6d621ee91aed68104ee9e474f3b66712404e92e72627b44e268e740938d4
rtf-objdata-decoded RTF \objdata at offset 0x1E50 1434 bytes