Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 8b4a585c30b4ea38…

MALICIOUS

RTF / .DOC

503.4 KB
MD5: 1911095db6f91a9074475b3fb785af35 SHA-1: d5bacc5ba2ac282f13424a1475ae218be1d2b4c5 SHA-256: 8b4a585c30b4ea38610606c29e98a593506026db34a7efc71f748a1ada0e7ca9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains an embedded OLE object with an \objupdate directive, indicating an attempt to exploit a vulnerability and trigger OLE activation. This strongly suggests the document is designed to download and execute a malicious payload. The specific exploit and payload are not identifiable from the provided heuristics, leading to an 'unknown family' classification.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001313.bin
39950bfc3b9903bff5f3e02f08fc4a163be68bac5e3911bb8610f19f9e2547ae
rtf-objdata-decoded RTF \objdata at offset 0x1313 34945 bytes