Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 7f46243e6146e1a9…

MALICIOUS

RTF / .DOC

15.2 KB First seen: 2021-09-23
MD5: 6a0546434b6a3f30f59f06a6761620e2 SHA-1: 5c72f79b3aaef103e1e31bfdfc50e394198d999a SHA-256: 7f46243e6146e1a9e0455d5a76e3d68169c7924508d6ccd014c1075a706c97c3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF document contains OLE object data and uses an \objupdate directive, indicating an attempt to exploit a vulnerability for code execution. The specific exploit is not detailed, but the presence of these elements strongly suggests a malicious document designed to be delivered as an attachment.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000f22.bin
cfb505b2b4323d0f57317c51d286a36aae2b432bcfb6cf9d101844a626208385
rtf-objdata-decoded RTF \objdata at offset 0xF22 1524 bytes