Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 9b9ffbdc1022f1b2…

MALICIOUS

RTF / .DOC

78.8 KB
MD5: cdbad2902e626007c7f18da970cb588a SHA-1: cea0f73da57be4cc31fa687b1bb345d7fbfde08a SHA-256: 9b9ffbdc1022f1b2e5fd4ad6f55a01ff7f36f74635b8d518838cd67deb1524fb
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The RTF document contains OLE object data and triggers an \objupdate heuristic, indicating it's designed to activate embedded objects. This strongly suggests an attempt to exploit vulnerabilities or deliver a secondary payload via the OLE object. No document body or script content was available for further analysis, limiting the ability to determine the specific lure or payload.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000016d8.bin
ec142c1fc83e7e554da2a2e25d0b79691cbf3338920083283f711327020d26c8
rtf-objdata-decoded RTF \objdata at offset 0x16D8 4213 bytes