Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 586c7eddeb7d6b8d…

MALICIOUS

RTF / .DOC

19.6 KB
MD5: 7d43e08ae3b9e20451f1a5a17e9534a6 SHA-1: 340fce367b16254585c1c18c3a14f55b670e9a4f SHA-256: 586c7eddeb7d6b8d9234a554ba08ed1d09bf2b1fb660769d937fe4c463d98ca0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains embedded OLE object data, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic suggests that this object is designed to be activated automatically, which is a common technique for exploiting vulnerabilities in document viewers like Microsoft Word. The presence of OLE object data strongly implies an attempt to execute embedded code or exploit a vulnerability upon opening the document. The exact nature of the exploit or payload is not clear from the provided heuristics and doc body, but the intent is likely to download and execute a second-stage payload.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001f57.bin
d02c3b5bfad3bea99e8be67aefbb2a67f4bcb8451308fa7a9333a0bd48956c82
rtf-objdata-decoded RTF \objdata at offset 0x1F57 1552 bytes