Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 600e9328c592417b…

MALICIOUS

RTF / .DOC

4.3 KB First seen: 2023-06-22
MD5: 8beb6d32ab7a3b9259846ed6c92ce55b SHA-1: 78ee1fcf7fabc1d9d56f62ac7854db23fd598e1a SHA-256: 600e9328c592417bfa986a5a2f7aca7503dcfde78d962d1e289bde8f890c1aae
60 Risk Score

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects