Malicious RTF — malware analysis report

Static analysis result for SHA-256 6b38ac5b7be8f62d…

MALICIOUS

RTF

4.3 KB
MD5: 7605e5995aeece78fa5b454fd168eb31 SHA-1: fcd7d994da25cc401fbea536cbdbeb33ca8ed587 SHA-256: 6b38ac5b7be8f62d0e7645cdd3553ac86a06ccbbd6de9865f5bdf00bf62822e6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF file contains OLE object data and uses an \objupdate directive, indicating it is designed to exploit a vulnerability in OLE object activation for client execution. No specific family could be identified from the available evidence.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000091.bin
49f5bed2f4fa77b65f7bb2b77316bbd2e6bd21597920505302ba54fbd8a8fe91
rtf-objdata-decoded RTF \objdata at offset 0x91 1695 bytes