Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 90dea16360ecfcdd…

MALICIOUS

RTF / .DOC

80.8 KB
MD5: 44bf8a02bded31b0ab0d2c07a4542501 SHA-1: 49ef2942c0ff793e113e64b0d3b9ade24f56d18d SHA-256: 90dea16360ecfcdd8807e16fa531accfc5d7b0b28900d46dd2e01b1e94978a6a
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The RTF document contains embedded OLE object data and triggers an \objupdate event, indicating an attempt to exploit RTF parsing vulnerabilities. This suggests a malicious attachment designed to execute embedded content, likely for further payload delivery or system compromise. The specific exploit or payload is not directly discernible from the provided RTF content alone.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001850.bin
f0a2f1ce9dd138e024e61bc5d7a85c5e82e5c3012c38c557550af233c9562206
rtf-objdata-decoded RTF \objdata at offset 0x1850 4200 bytes