Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 a6c3546e1a6aa4d4…

MALICIOUS

RTF / .DOC

19.3 KB
MD5: c8bf28450e19717ea1b29e483d2a2e8d SHA-1: acf6ac8cb44ca7dcf8403b4c9ca0fa10dbd466f6 SHA-256: a6c3546e1a6aa4d4dfd21accc59112514ef7bad026d362e3546cad25466bf1b9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The RTF document contains OLE object data and a high-severity RTF_OBJUPDATE heuristic firing, indicating that embedded objects are likely being activated. No document body or script content was available for further analysis. The presence of OLE object data suggests an attempt to embed and execute malicious content, potentially leading to further stages of an attack.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001585.bin
05fc3417328a63281fdb26508582b5fa8d6655eb5d494c5ec756a074f2cde309
rtf-objdata-decoded RTF \objdata at offset 0x1585 1780 bytes