Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 b5f86fe806b443b6…

MALICIOUS

RTF / .DOC

70.2 KB
MD5: ae2b9d1bf41e1c295fc8a50830fd8d5f SHA-1: 340022911917895e944185c4dfc18087e9d5fd69 SHA-256: b5f86fe806b443b6627d369f3a2e036eea553a2206192df11705e1f23847f507
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The RTF document contains OLE object data and uses \objupdate to force OLE activation, indicating an attempt to exploit a vulnerability related to embedded objects. The high severity heuristic for \objupdate suggests a malicious intent to trigger code execution. No specific family could be identified, and no further IOCs were extracted.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off000011f9.bin
f1db4e347ad9bf86da3c801845e17c4b2bbdc702fcf9bf0e0c0cd7733e0d14ad
rtf-objdata-decoded RTF \objdata at offset 0x11F9 3753 bytes