Malicious RTF — malware analysis report

Static analysis result for SHA-256 6c6443780e3a3306…

MALICIOUS

RTF

25.1 KB First seen: 2023-06-13
MD5: 0191b68971c6f07c59ad7ca657247345 SHA-1: 01841a6f9e6002f6525318943c90c6c797c19350 SHA-256: 6c6443780e3a3306beb61ee3d5b646f68707142b0819859c3a9c33839d86d9b6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File Execution: User Execution

The RTF file contains OLE object data and uses \objupdate to force OLE activation, indicating an attempt to exploit a vulnerability. The presence of RTF_OBJDATA and RTF_OBJUPDATE heuristics strongly suggests a malicious RTF document designed to execute embedded content. No document body or script content was available for further analysis.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001a1b.bin
1a4c478dfaaf4e7bdca22739cdd13802e21e3117d6d6722988a1bd37b6865708
rtf-objdata-decoded RTF \objdata at offset 0x1A1B 3675 bytes