Malicious RTF — malware analysis report

Static analysis result for SHA-256 9eb83d3c64ec1123…

MALICIOUS

RTF

375.2 KB First seen: 2019-01-12
MD5: 5191700c69f02bdec39b2a4ae2def51b SHA-1: 9ab6887a743e32360beaa197782911c68e70fe25 SHA-256: 9eb83d3c64ec11235e3b457de3037e50fa0a469a2e0907e06ec39777033d1f3b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The RTF file contains OLE object data and an \objupdate directive, indicating an attempt to exploit a vulnerability related to OLE object activation. This suggests the file is designed to execute arbitrary code upon opening. No document body or script content was available for further analysis.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001cbb.bin rtf-objdata-decoded RTF \objdata at offset 0x1CBB 2199 bytes
SHA-256: fd0621f10f72c2daf86166a0d0400fd060ecc71f6acde2985014ada36d4f2aaa