Malicious RTF — malware analysis report

Static analysis result for SHA-256 af822088e82ed32f…

MALICIOUS

RTF

4.4 KB First seen: 2023-10-03
MD5: 8983cf278c6f06788003c170b6d8cc6d SHA-1: 8e6152dc70229aa904913f3f90d7d989609e17c0 SHA-256: af822088e82ed32f7c78634da68a2f9baa8fd3b58f3b53b18120c5a0ddd67d11
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains embedded OLE objects, with heuristics indicating that \objupdate forces OLE activation. This suggests the file is designed to exploit OLE vulnerabilities to execute arbitrary code upon opening. The specific exploit mechanism is not detailed, but the presence of OLE objects points towards a common delivery method for malware.

Heuristics 3

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000008e.bin
52edd2963574a9940588a7c7e2d7a76a03b9b72bf268cff6a667edef4364613d
rtf-objdata-decoded RTF \objdata at offset 0x8E 2122 bytes