Malicious RTF — malware analysis report

Static analysis result for SHA-256 649f2cd33a1fe05e…

MALICIOUS

RTF

115.2 KB First seen: 2022-07-02
MD5: 727ffe591df683b9f0d2c8cd2977a829 SHA-1: 67baabe59b9bb76cca9dad9267dfbb34dd9c5218 SHA-256: 649f2cd33a1fe05ee7c4840ae3f1e6d9b4885275ec264c768c3673a280823398
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF file contains an OLE object with ".objupdate" directive, indicating an attempt to exploit a vulnerability and execute code upon opening. The specific exploit and resulting payload are not discernible from the provided evidence, leading to an unknown family classification.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000008a.bin rtf-objdata-decoded RTF \objdata at offset 0x8A 42170 bytes
SHA-256: cc9554ec489928b923fce96e141702fcaa964339885c67bd685248db6f5be49f