Malware Insights
The RTF file contains an embedded OLE object, indicated by the RTF_OBJDATA and RTF_OBJEMB heuristics. The RTF_OBJUPDATE heuristic suggests that the object is configured to automatically activate, which is a common technique for delivering malicious payloads. While the document body is minimal and the embedded URL is benign, the presence and configuration of the OLE object strongly suggest an attempt to exploit user interaction or automatic activation to execute arbitrary code. The specific nature of the payload within the OLE object could not be determined from the provided evidence.
Heuristics 4
-
\objupdate forces OLE activation high RTF_OBJUPDATERTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
-
OLE object data medium RTF_OBJDATARTF contains 1 \objdata section(s) — embedded OLE objects
-
Embedded OLE object medium RTF_OBJEMBRTF contains \objemb — embedded OLE object
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://schemas.microsoft.com/office/word/2003/wordml
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
objdata_00_off000089bf.bin8f7e01dcdab1e7a437befa2df92fb3451974ea9b59e916fa2fa0d746341aa694 |
rtf-objdata-decoded | RTF \objdata at offset 0x89BF | 15672 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.