Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 679c9808ff930cd0…

MALICIOUS

RTF / .DOC

12.1 KB First seen: 2022-04-21
MD5: 4a1485766ce2eb9122e5292491b88348 SHA-1: e56429ae02fb6d3ff523458730f956f9da4ab0c3 SHA-256: 679c9808ff930cd0ce84ad801d8a784cbdf2abe0fd4fc9585321640c1493269c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF document contains OLE object data and an \objupdate directive, indicating an attempt to exploit a vulnerability for code execution. While no specific script was directly extracted, the presence of RTF object data suggests a potential for embedded exploits that could lead to the execution of arbitrary code, possibly by leveraging a vulnerability to run a secondary payload. The confidence is moderate due to the lack of explicit script content.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001aa9.bin
ad03e8d8fdceb198ab48f0b068aba4a84f68b4effc07ad94a8de85a5b93d97a2
rtf-objdata-decoded RTF \objdata at offset 0x1AA9 1699 bytes