Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 86ac4ad3c24e0739…

MALICIOUS

RTF / .DOC

90.5 KB
MD5: 3cf1e59edc3c0a467973b0b23a990651 SHA-1: fea6ebb2713dd25f03c16a1f107d69134ca62c2d SHA-256: 86ac4ad3c24e0739255ba7859c0e387a566d0a6a65bd41d313bbe65468cb409c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF document contains an embedded OLE object, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic suggests that this object is configured to automatically activate, which is a common technique for executing embedded exploits or payloads. The specific nature of the OLE object and its payload could not be determined from the available evidence.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000075.bin
86efada2d8f583a4f51cba96ba6fb8e017aa1a531045be8f123472dd9bca4af4
rtf-objdata-decoded RTF \objdata at offset 0x75 28606 bytes