Malicious RTF — malware analysis report

Static analysis result for SHA-256 b82acfb193e00c65…

MALICIOUS

RTF

25.6 KB First seen: 2023-05-17
MD5: 047fef24cc2235db39d3eb1551be28bf SHA-1: 9e32476d35becabcdb435eb1dfe26fa50dd25318 SHA-256: b82acfb193e00c6506c2712e7d7a15e875e0f37b9a964c689c926c79d459d81d
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious File

The RTF file contains embedded OLE object data and an \objupdate directive, indicating an attempt to automatically execute embedded content upon opening. This is a common technique for delivering malicious payloads. While no specific family is identified, the method strongly suggests a downloader or exploit delivery mechanism.

Heuristics 2

  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off0000140c.bin
5ac567d73a5c7d5da16e447d555c1cc46aa30a396ce1e35cd9be8e11d7ff929d
rtf-objdata-decoded RTF \objdata at offset 0x140C 4172 bytes