Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 a4f5010c998cf8fc…

MALICIOUS

RTF / .DOC

3.9 KB First seen: 2023-06-10
MD5: b2376b5b15d1bd53f1f0dce3caf508a6 SHA-1: b27cbaddcf2a69e193da0d3e80b938685b44d549 SHA-256: a4f5010c998cf8fc3dd81dff7296ed17f975483d0a1bb3a73d89d4bd6c403ce4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains an OLE object that is configured to automatically update and activate. This behavior is indicative of a malicious document designed to exploit vulnerabilities or deliver a secondary payload upon opening. The presence of the \objupdate directive strongly suggests an attempt to trigger embedded malicious content.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000084.bin
826bc15ee517ed81bfd73206f01c160830a30b936b59e6b5becf12bd4e841e18
rtf-objdata-decoded RTF \objdata at offset 0x84 1905 bytes