Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 a78f957f97c635c0…

MALICIOUS

RTF / .DOC

6.7 KB First seen: 2023-05-31
MD5: 23cfb8a26a00b24b44825084b2309655 SHA-1: 9cfa9008ef852961b8ab986f424f1bf043b152c2 SHA-256: a78f957f97c635c0c4913f101e3960058696804d6d2856d70259e36cbbd10b07
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The RTF document contains OLE object data and an \objupdate directive, indicating an attempt to exploit OLE object activation. This suggests the file is designed to deliver a malicious payload when opened. No specific malware family could be identified from the available heuristics.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000009e0.bin
68aa9047f0aba3d2359e45fd6feae4adb11dd05900ea498e4689130436c286a7
rtf-objdata-decoded RTF \objdata at offset 0x9E0 2124 bytes