Malicious RTF — malware analysis report

Static analysis result for SHA-256 a93ce8419e518bfe…

MALICIOUS

RTF

232.7 KB Created: 2021-02-12 04:30:00
MD5: 02c825165a573136b119f41425dcc0aa SHA-1: a145827c456b02362f8e364aadb0a9f4f012044d SHA-256: a93ce8419e518bfe693c0fd4d3dc3b163ae8f44c1ce188afac21190b3cf7ad36
82 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The RTF file contains embedded OLE objects, and a ".\objupdate" heuristic indicates that the file attempts to force the activation of these objects. This suggests an attempt to exploit vulnerabilities or execute embedded code, likely as part of a spearphishing attachment. The document body content appears to be a list of schools, which may serve as a lure.

Heuristics 4

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000106.bin
b6672225d9f8d8c8cb8104de1d4609cedc3b6fe52851a728983820cd66749e1d
rtf-objdata-decoded RTF \objdata at offset 0x106 913 bytes