Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 67eb0a1dc27b747f…

MALICIOUS

RTF / .DOC

11.2 KB First seen: 2022-06-03
MD5: 47bcbb3f2a8b515df9d4eb01fc9197f7 SHA-1: c6a0651ec59036d6376860465a3a1f00bfc2b87d SHA-256: 67eb0a1dc27b747fa19c49088890d70fd5a711e07b5f1507a3574e4f9a308440
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF document contains OLE object data and an \objupdate directive, indicating an attempt to embed and activate external content. This suggests the file is designed to exploit vulnerabilities or execute embedded code upon opening. The presence of OLE object data is a strong indicator of malicious intent, likely for delivering a secondary payload.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000162a.bin
39e8edab57b219609cc3a804a9d8b3093b07cbf1750ac890d6262fde8a4402fb
rtf-objdata-decoded RTF \objdata at offset 0x162A 1787 bytes