Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 77af2e0cd82f9f89…

MALICIOUS

RTF / .DOC

9.3 KB
MD5: 1e0dce9b634a2075ef06c5c0b2db60e7 SHA-1: 5662e5f40cb66495cd85592a3b2cd319703b56dc SHA-256: 77af2e0cd82f9f8906c446f0dc990bec15a74a3e5d7605ca3ac3660ef57247e8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF document contains OLE object data and uses an \objupdate directive, indicating an attempt to exploit OLE activation for code execution. This is a common technique for delivering secondary payloads. While no specific family is identifiable, the method strongly suggests a malicious intent to compromise the user's system.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001258.bin
622f45c8a466c514fdb80149b856b4b651359448ee99aa60e80a7d0563997b80
rtf-objdata-decoded RTF \objdata at offset 0x1258 1511 bytes