Malicious RTF — malware analysis report

Static analysis result for SHA-256 53dced2862d890b9…

MALICIOUS

RTF

3.3 KB First seen: 2022-12-07
MD5: 7a7d9b82e6d26b4d575ac0a5cd93faff SHA-1: ce64d85889744473fa305c3e51cd50c58fb4a7ce SHA-256: 53dced2862d890b9c606cf475d09241f33dda53eb131af8a501ce1453b0aa56d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains embedded OLE object data, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic suggests that this embedded object is designed to be automatically activated upon opening the document, likely leading to the execution of malicious code. The specific exploit targeted is not detailed, but the mechanism points to a classic OLE object abuse for initial execution.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000072.bin
1a2291ba36e57e19fd06787b615cd1e061314e044cc6e69cf9230ce935a90612
rtf-objdata-decoded RTF \objdata at offset 0x72 1565 bytes