Malicious RTF — malware analysis report

Static analysis result for SHA-256 94c0bab05cf2e69d…

MALICIOUS

RTF

9.9 KB
MD5: 977348cc0f9d6f2f28671f65c7f7642c SHA-1: 4c0cb94d9ced9d2e178a955d5907492a209a4711 SHA-256: 94c0bab05cf2e69d0b1e087df7f8c3dfed49d2cbe55c72f6a291a2de46eb01c7
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF file contains OLE object data and uses \objupdate to force OLE activation, indicating an attempt to exploit a vulnerability. The embedded OLE object is likely designed to download and execute a second-stage payload. While no specific family is identified, the technique suggests a common delivery method for malware.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000010f4.bin
f5d84f788c9ff0ec9ce0000f266495af730d73c2ddebd34672146d9a9b988552
rtf-objdata-decoded RTF \objdata at offset 0x10F4 1795 bytes