Malicious RTF — malware analysis report

Static analysis result for SHA-256 b5e6c895aa126c87…

MALICIOUS

RTF

15.7 KB First seen: 2020-02-04
MD5: 5112153b62715b9caf2846e86d264a8d SHA-1: 544edfdcd0b8b150024863d78a485f5e7a1121f4 SHA-256: b5e6c895aa126c87b58cc1cbfcb5c101dca8fe396bcadadac985dabbbff2bd78
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains embedded OLE object data and uses an \objupdate directive, indicating an attempt to exploit a vulnerability for code execution. While no specific payload or URL was directly extracted, the presence of these elements strongly suggests the file is designed to download and execute a secondary malicious component. The file's structure and heuristic firings point towards a common technique for delivering malware via email attachments.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000000fe.bin rtf-objdata-decoded RTF \objdata at offset 0xFE 932 bytes
SHA-256: 02941eb042eb31bdc4157eda17e42b19b552b468963b53fa6abf877dd014797c