Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 7e3034b8567eb200…

MALICIOUS

RTF / .DOC

75.5 KB
MD5: a3879de22d288fb35272e5fdc16203d6 SHA-1: 5a697a09278a10afc2e8fd8a53401128ab2f1a33 SHA-256: 7e3034b8567eb200c7b7802c47bd065fd1cfcc3661dd013b38b6af01195929a3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The RTF file contains OLE object data and an \objupdate directive, indicating it's designed to activate embedded objects. This strongly suggests a malicious intent to exploit OLE vulnerabilities or trick the user into opening embedded content. While no specific script was extracted, the presence of OLE objects points towards a delivery mechanism for further malicious activity. The SHA256 hash is included as a primary identifier.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000f5c.bin
8079662bb5a8ada0d71894e60a4b70aa30c90f47a8e0bcb6f15c85c6ecb5523c
rtf-objdata-decoded RTF \objdata at offset 0xF5C 4167 bytes