Malicious RTF — malware analysis report

Static analysis result for SHA-256 688ade2a84dc563d…

MALICIOUS

RTF

487.5 KB First seen: 2024-06-28
MD5: 737355ad732da62afc3eca04aaefbc25 SHA-1: 19d6816b326e076e33ba21df51c328685f59bd75 SHA-256: 688ade2a84dc563da3868c853dc6df1150d07ba094f0e6ee0eff9cb6b3faf938
100 Risk Score

Malware Insights

MITRE ATT&CK
T1204 User Execution T1204.002 Malicious File T1566 Phishing T1566.001 Spearphishing Attachment

The RTF file contains embedded OLE objects and an instruction to 'enable editing', indicating a social engineering lure to bypass security measures. The presence of ".objdata" and ".objupdate" heuristics strongly suggests the activation of embedded OLE objects, which is a common method for delivering malicious payloads. The document body discusses financial auditing, likely serving as a pretext to disguise the malicious intent.

Heuristics 4

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Macro/content-enable lure medium SE_ENABLE_LURE
    Document instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0002bbab.bin
ea3ecb45d624dd4e242eb4b9fc739c535897174a02478c5e0bb658d55ddc2911
rtf-objdata-decoded RTF \objdata at offset 0x2BBAB 1391 bytes