Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 b06066baf8991b23…

MALICIOUS

RTF / .DOC

59.5 KB
MD5: 400cdb6cfadec02aed22b957ceef333d SHA-1: 84c501c2f32e81b21c44780e3dfbbbb0cb06906e SHA-256: b06066baf8991b238422d792d21ce359212bed45d7ca561883bb50ba26686e4f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains embedded OLE objects, indicated by the RTF_OBJDATA and RTF_OLE10NATIVE_STREAM heuristics. The RTF_OBJUPDATE heuristic suggests that these objects are designed to be automatically activated upon opening the document, leading to arbitrary code execution. No specific document body text or scripts were extracted, so the exact payload and delivery mechanism remain unknown.

Heuristics 3

  • Ole10Native stream in RTF OLE object high CVE related RTF_OLE10NATIVE_STREAM
    RTF contains an embedded OLE object with an Ole10Native stream. This is a strong payload-container signal and is related to Word/OLE exploit delivery, but it is not specific enough on its own to assign a CVE.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000906.bin
0b84c5402ed87b93c8e1a96283929ebed04a5987d97e83606475753d0c65bf44
rtf-objdata-decoded RTF \objdata at offset 0x906 4146 bytes