Malicious RTF — malware analysis report

Static analysis result for SHA-256 af88086eeca5fd11…

MALICIOUS

RTF

23.8 KB First seen: 2023-05-23
MD5: 05ec34c0d8db1ff6e5def9ab587dadc8 SHA-1: d87e6f279b769dd4a1cea007f3503db5a4c4a47a SHA-256: af88086eeca5fd1111c4d054eecf72d497d603b9d8d80184ef0c1adc26c97aa9
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The sample is an RTF file containing OLE object data, indicated by the RTF_OBJDATA heuristic. The RTF_OBJUPDATE heuristic at offset 0x1683 suggests that the embedded OLE object is designed to be activated automatically, likely leading to the execution of malicious code. The presence of OLE objects within RTF documents is a common technique for delivering secondary payloads.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000016a5.bin
440b1528d5b2b211d78d4e76c3781f3027dc8b523d107c9a5aaf6f2dcf44b8d7
rtf-objdata-decoded RTF \objdata at offset 0x16A5 3656 bytes