Malicious RTF — malware analysis report

Static analysis result for SHA-256 915d3671b676c842…

MALICIOUS

RTF

12.8 KB First seen: 2020-08-25
MD5: 2e72a053bf09d29401a9eaf0cb196b49 SHA-1: 90e6f2832a76a5bf5e791f9f18fa80aa52f460ae SHA-256: 915d3671b676c842be045ce0a988511fd5740acb1f6448ebc388dcef92184fe1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF document contains OLE object data and a \objupdate directive, indicating an attempt to exploit a vulnerability for client execution. The presence of embedded OLE object data suggests a malicious payload is likely being delivered. The specific exploit and payload are not directly discernible from the provided evidence, leading to an unknown family classification.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00002106.bin rtf-objdata-decoded RTF \objdata at offset 0x2106 2060 bytes
SHA-256: ec29ad7d17bc94951a991bb9ddf38fd1823536b95b9cded51becc7d1fc5331f4