Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 5b4dacdaaf4f3f39…

MALICIOUS

RTF / .DOC

20.5 KB
MD5: 93b16b2225201835d9fe1a4e23ae0d2d SHA-1: a1c3bb28104aff5f1c17f51c1b796e5d82810c91 SHA-256: 5b4dacdaaf4f3f3913acb3507196147f494df5f5d02056e98d0593de7b6d281f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF document contains OLE object data and an \objupdate directive, indicating an attempt to exploit a vulnerability and activate embedded objects. This is a common technique for delivering malicious payloads. The specific exploit and payload are not discernible from the provided evidence, leading to an unknown family classification.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001026.bin
0e163ba73d597fc831987e5247dde42486c60eb6c4d5d9178b24c2a63ac050e8
rtf-objdata-decoded RTF \objdata at offset 0x1026 1675 bytes