Malicious RTF — malware analysis report

Static analysis result for SHA-256 724f71065484f1f9…

MALICIOUS

RTF

26.1 KB First seen: 2019-05-10
MD5: 21a5dc826c813c146aca6628b5f0570c SHA-1: af85ee360087478dded4264d060035cc52056043 SHA-256: 724f71065484f1f9afc80c604fcd3495d033b316f6a9a3548aa9c4895f5e9c02
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains embedded OLE object data and an \objupdate directive, indicating an attempt to exploit OLE activation for code execution. The presence of an embedded URL, though benign, suggests a potential download mechanism. The document body is heavily obfuscated and does not provide clear textual lures, but the heuristics strongly suggest a malicious OLE object execution.

Heuristics 3

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000058d1.bin rtf-objdata-decoded RTF \objdata at offset 0x58D1 1582 bytes
SHA-256: 00db578180dcca0f440a4d617c35791c30d85a0daa2b5c78eaaaaa5dff6d35ba