Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 578684dbaa632549…

MALICIOUS

RTF / .DOC

189.4 KB First seen: 2023-01-23
MD5: ef12d334dcd5b8144530ed0f29508837 SHA-1: 367244325fbe4d7073eaeec476bdcccf4f1c6b3a SHA-256: 578684dbaa63254933f65e2d8d0f5a5b080a55a7dd5a7a88e4792fee7d8cd55a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains an embedded OLE object that is triggered via \objupdate, indicating an attempt to exploit a vulnerability. The presence of OLE object data strongly suggests the execution of embedded malicious code, likely for initial access or payload delivery.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000072.bin
4e6796fcd9b9826ca4697b1270443b34f8c69153a4d8933a5c51fbb92e8edd95
rtf-objdata-decoded RTF \objdata at offset 0x72 64184 bytes