Malicious RTF — malware analysis report

Static analysis result for SHA-256 67f52f10d1fc5ae6…

MALICIOUS

RTF

5.3 KB First seen: 2022-11-15
MD5: 9ecade1fa6e7d066636d879ac17184b4 SHA-1: 28e6557676619399b097c05fa9066af26568782f SHA-256: 67f52f10d1fc5ae68c914ca5b043b31adefdb797a1045d385aae2437a6369e72
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains OLE object data and an \objupdate directive, indicating it is designed to exploit vulnerabilities related to OLE object activation. This suggests a malicious document intended to deliver a payload upon opening.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000077.bin
35a89b5cc450d7c49b2ea994bccf9bf9f46ffd11868ead2bab1012715e72f06a
rtf-objdata-decoded RTF \objdata at offset 0x77 2426 bytes