Malicious RTF — malware analysis report

Static analysis result for SHA-256 55b5ca0aa5b439fd…

MALICIOUS

RTF

202.6 KB First seen: 2024-08-27
MD5: 603f3fc7d36b263a35aebc03ca35ee34 SHA-1: f53c97bd23c8930b5e1e51758f415f30dffb2898 SHA-256: 55b5ca0aa5b439fd0675b65d99dcc0ad611d1d73ef2486820e99365a92e91d00
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The RTF file contains OLE object data and a \objupdate directive, indicating an attempt to execute embedded content. While no specific document body or script content was extracted for direct analysis, the presence of these RTF-specific indicators strongly suggests a malicious intent, likely to exploit vulnerabilities or deliver a payload via the embedded OLE object. The objdata section itself is listed as an IOC.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000b36.bin
ef8282c74a45e9838a737016b6fdaa2885e816f7a1c9e0eba9d890bbfaa7f441
rtf-objdata-decoded RTF \objdata at offset 0xB36 4179 bytes